Server-Side Request Forgery Vulnerability in SAP NetWeaver AS JAVA
CVE-2020-6282

5.8MEDIUM

Summary

SAP NetWeaver AS JAVA, specifically targeting the IIOP service and CORE-TOOLS versions from 7.10 to 7.50, is susceptible to a server-side request forgery (SSRF) vulnerability. This weakness allows attackers to send specially crafted requests that can manipulate internal system resources, which are typically protected by firewalls. By exploiting this vulnerability, an attacker could gain unauthorized access to internal systems, posing a risk to data security and integrity.

Affected Version(s)

SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS) < 7.10 < 7.10

SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS) < 7.11 < 7.11

SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS) < 7.20 < 7.20

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.