PT-2020-19072 · Sap · Abap Platform+2

Published

2020-07-14

·

Updated

2022-10-05

·

CVE-2020-6280

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver (ABAP Server) and ABAP Platform versions 731, 740, 750
Description The issue allows an attacker with admin privileges to access certain files that should otherwise be restricted, leading to information disclosure.
Recommendations For versions 731, 740, 750, consider restricting access to sensitive files until a patch is available. As a temporary workaround, limit the privileges of administrators to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2020-6280

Affected Products

Abap Platform
Abap Server
Sap Netweaver