cbcvebase.
CVE-2020-6280
published 2020-07-14

CVE-2020-6280: SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise…

PriorityP49low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.94%
56.8th percentile
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.

Affected

9 ranges
VendorProductVersion rangeFixed in
sapabap_platform
sapabap_platform
sapabap_platform
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sap_sesap_netweaver_and_abap_platform< 731731
sap_sesap_netweaver_and_abap_platform< 740740
sap_sesap_netweaver_and_abap_platform< 750750

CVSS provenance

nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv3.02.7LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.