cbcvebase.
CVE-2020-6263
published 2020-06-10

CVE-2020-6263: Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity leading to Authentication Bypass.

Affected

24 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sap_sesap_netweaver_as_java< SAP-JEECOR 7.00SAP-JEECOR 7.00
sap_sesap_netweaver_as_java< 7.01 SERVERCOR 7.107.01 SERVERCOR 7.10
sap_sesap_netweaver_as_java< 7.117.11
sap_sesap_netweaver_as_java< 7.207.20
sap_sesap_netweaver_as_java< 7.307.30
sap_sesap_netweaver_as_java< 7.317.31
sap_sesap_netweaver_as_java< 7.407.40
sap_sesap_netweaver_as_java< 7.50 CORE-TOOLS 7.007.50 CORE-TOOLS 7.00
sap_sesap_netweaver_as_java< 7.017.01
sap_sesap_netweaver_as_java< 7.027.02
sap_sesap_netweaver_as_java< 7.057.05
sap_sesap_netweaver_as_java< 7.107.10
sap_sesap_netweaver_as_java< 7.507.50