CVE-2020-6263
EUVD-2020-2741310.06.2020, 13:15
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity leading to Authentication Bypass.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver_application_server_java | 7.00 |
| sap | netweaver_application_server_java | 7.01 |
| sap | netweaver_application_server_java | 7.02 |
| sap | netweaver_application_server_java | 7.05 |
| sap | netweaver_application_server_java | 7.10 |
| sap | netweaver_application_server_java | 7.11 |
| sap | netweaver_application_server_java | 7.20 |
| sap | netweaver_application_server_java | 7.30 |
| sap | netweaver_application_server_java | 7.31 |
| sap | netweaver_application_server_java | 7.40 |
| sap | netweaver_application_server_java | 7.50 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration