CVE Vulnerabilities

CVE-2020-6280

Published: Jul 14, 2020 | Modified: Nov 21, 2024
CVSS 3.x
2.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.

Affected Software

NameVendorStart VersionEnd Version
Abap_platformSap7.31 (including)7.31 (including)
Abap_platformSap7.40 (including)7.40 (including)
Abap_platformSap7.50 (including)7.50 (including)
Netweaver_application_server_abapSap731 (including)731 (including)
Netweaver_application_server_abapSap740 (including)740 (including)
Netweaver_application_server_abapSap750 (including)750 (including)

References