PT-2020-19068 · Sap · Sap Netweaver As Abap
Published
2020-06-10
·
Updated
2022-10-05
·
CVE-2020-6275
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Netweaver AS ABAP versions 700 through 754
Description
The issue allows an attacker to perform a Server Side Request Forgery Attack by using inappropriate path names containing malicious server names in the import/export of sessions functionality. This can coerce the web server into authenticating with the malicious server. If NTLM is set up, the attacker can compromise the confidentiality, integrity, and availability of the SAP database.
Recommendations
For SAP Netweaver AS ABAP versions 700 through 754, consider restricting the import/export of sessions functionality to prevent the use of malicious server names until a patch is available. As a temporary workaround, review and secure NTLM setup to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As Abap