cbcvebase.
CVE-2020-6286
published 2020-07-14

CVE-2020-6286: The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.

Affected

8 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sap_sesap_netweaver_as_java< 7.307.30
sap_sesap_netweaver_as_java< 7.317.31
sap_sesap_netweaver_as_java< 7.407.40
sap_sesap_netweaver_as_java< 7.507.50