PT-2020-5169 · Sap · Abap Platform+2
Published
2020-08-12
·
Updated
2022-10-05
·
CVE-2020-6310
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver (ABAP Server) and ABAP Platform versions 702, 730, 731, 740, 750
Description
The issue is related to improper access control in the SOA Configuration Trace component, allowing any authenticated user to enumerate all SAP users. This leads to information disclosure. The vulnerability is also described as a lack of protection for service data, which can be exploited by a remote attacker to disclose protected information.
Recommendations
For versions 702, 730, 731, 740, 750, consider restricting access to the SOA Configuration Trace component to minimize the risk of exploitation.
As a temporary workaround, consider disabling the enumeration of SAP users until a patch is available.
Restrict access to service data to prevent remote attackers from disclosing protected information.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abap Platform
Abap Server
Sap Netweaver