Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity leading to Authentication Bypass.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2878568 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-06-10 06:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-6263
Mitre link : CVE-2020-6263
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
sap
- netweaver_application_server_java