Vulnerability Intelligence Report
CVE-2020-6286
The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.
No Active Exploit Signals
CVSS Base Score
5.3
MEDIUM
Exploitability:3.9
Impact Score:1.5
EPSS Probability:28.31%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP SE | SAP NetWeaver AS JAVA (LM Configuration Wizard) | < 7.30 (affected), < 7.31 (affected), < 7.40 (affected), < 7.50 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
28.312%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2020-01-08T00:00:00 |
| Published | 2020-07-14T12:30:14 |
| Last Updated | 2024-08-04T08:55:22 |
Community Chatter & Buzz