cbcvebase.
CVE-2020-6310
published 2020-08-12

CVE-2020-6310: Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapabap_platform
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sapnetweaver_application_server_abap
sap_sesap_netweaver_and_abap_platform< 702702
sap_sesap_netweaver_and_abap_platform< 730730
sap_sesap_netweaver_and_abap_platform< 731731