PT-2020-5169 · Sap · Abap Platform+2

Published

2020-08-12

·

Updated

2022-10-05

·

CVE-2020-6310

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver (ABAP Server) and ABAP Platform versions 702, 730, 731, 740, 750
Description The issue is related to improper access control in the SOA Configuration Trace component, allowing any authenticated user to enumerate all SAP users. This leads to information disclosure. The vulnerability is also described as a lack of protection for service data, which can be exploited by a remote attacker to disclose protected information.
Recommendations For versions 702, 730, 731, 740, 750, consider restricting access to the SOA Configuration Trace component to minimize the risk of exploitation. As a temporary workaround, consider disabling the enumeration of SAP users until a patch is available. Restrict access to service data to prevent remote attackers from disclosing protected information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2020-05780
CVE-2020-6310

Affected Products

Abap Platform
Abap Server
Sap Netweaver