CVE-2020-26816
published 2020-12-09CVE-2020-26816: SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key…
PriorityP421medium4.5CVSS 3.1
AVAACLPRHUINSUCHINAN
EPSS
0.17%
6.3th percentile
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver AS Java to decode the keys because of missing encryption and get some application data and client credentials of adjacent systems. This highly impacts Confidentiality as information disclosed could contain client credentials of adjacent systems.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap | netweaver_application_server_java | — | — |
| sap_se | sap_netweaver_as_java | < 7.10 | 7.10 |
| sap_se | sap_netweaver_as_java | < 7.11 | 7.11 |
| sap_se | sap_netweaver_as_java | < 7.20 | 7.20 |
| sap_se | sap_netweaver_as_java | < 7.30 | 7.30 |
| sap_se | sap_netweaver_as_java | < 7.31 | 7.31 |
| sap_se | sap_netweaver_as_java | < 7.40 | 7.40 |
| sap_se | sap_netweaver_as_java | < 7.50 | 7.50 |
CVSS provenance
nvdv3.14.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-09
Published