cbcvebase.
CVE-2020-6287
published 2020-07-14

CVE-2020-6287: SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
94.72%
99.8th percentile
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

Affected

8 ranges
VendorProductVersion rangeFixed in
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sapnetweaver_application_server_java
sap_sesap_netweaver_as_java< 7.307.30
sap_sesap_netweaver_as_java< 7.317.31
sap_sesap_netweaver_as_java< 7.407.40
sap_sesap_netweaver_as_java< 7.507.50

Detection & IOCsextracted from sources · hover to see the quote

pathhttp/cves/2020/CVE-2020-6287.yaml
pathmodules/auxiliary/admin/sap/cve_2020_6287_ws_add_user.rb
snort
Snort SIDs: 54571 - 54574
  • CVE-2020-6287 (RECON) exploits the unauthenticated LM Configuration Wizard in SAP NetWeaver AS JAVA. Detect exploitation attempts by monitoring for unauthenticated requests to the LM Configuration Wizard web service endpoint, particularly job-submission requests that attempt to create administrative users.
  • Mass scanning activity for CVE-2020-6287 was observed shortly after PoC publication. Monitor SAP NetWeaver AS JAVA HTTP(S) ports for anomalous unauthenticated probe traffic.
  • Use the Nuclei template http/cves/2020/CVE-2020-6287.yaml (chained after SAP NetWeaver detection) to identify vulnerable SAP NetWeaver instances.
  • Apply Snort SIDs 54571–54574 to detect CVE-2020-6287 exploitation attempts against SAP NetWeaver AS JAVA LM Configuration Wizard.
  • Check Point IPS blade signature 'SAP NetWeaver Directory Traversal (CVE-2020-6286)' is noted as providing protection in the same advisory context as CVE-2020-6287; monitor IPS logs for related SAP NetWeaver alerts.
  • ·CVE-2020-6287 is exploitable under default SAP NetWeaver AS JAVA configurations (versions 7.30, 7.31, 7.40, 7.50); no special misconfiguration is required for the attack to succeed.
  • ·The Metasploit module cancels the wizard job after user creation to minimise unnecessary system changes, meaning forensic artefacts of the job may be short-lived; defenders should log all wizard job creation and cancellation events.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.