PT-2020-19068 · Sap · Sap Netweaver As Abap

Published

2020-06-10

·

Updated

2022-10-05

·

CVE-2020-6275

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Netweaver AS ABAP versions 700 through 754
Description The issue allows an attacker to perform a Server Side Request Forgery Attack by using inappropriate path names containing malicious server names in the import/export of sessions functionality. This can coerce the web server into authenticating with the malicious server. If NTLM is set up, the attacker can compromise the confidentiality, integrity, and availability of the SAP database.
Recommendations For SAP Netweaver AS ABAP versions 700 through 754, consider restricting the import/export of sessions functionality to prevent the use of malicious server names until a patch is available. As a temporary workaround, review and secure NTLM setup to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2020-6275

Affected Products

Sap Netweaver As Abap