← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-6286

The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.

No Active Exploit Signals
CVSS Base Score
5.3
MEDIUM
Exploitability:3.9
Impact Score:1.5
EPSS Probability:28.31%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
SAP SE SAP NetWeaver AS JAVA (LM Configuration Wizard) < 7.30 (affected), < 7.31 (affected), < 7.40 (affected), < 7.50 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
28.312%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2020-01-08T00:00:00
Published2020-07-14T12:30:14
Last Updated2024-08-04T08:55:22

LINK COPIED TO CLIPBOARD