CVE Vulnerabilities

CVE-2020-6310

Published: Aug 12, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.

Affected Software

NameVendorStart VersionEnd Version
Abap_platformSap7.31 (including)7.31 (including)
Abap_platformSap7.40 (including)7.40 (including)
Abap_platformSap7.50 (including)7.50 (including)
Abap_platformSap700 (including)700 (including)
Abap_platformSap701 (including)701 (including)
Abap_platformSap702 (including)702 (including)
Abap_platformSap710 (including)710 (including)
Abap_platformSap711 (including)711 (including)
Abap_platformSap751 (including)751 (including)
Abap_platformSap753 (including)753 (including)
Abap_platformSap755 (including)755 (including)
Netweaver_application_server_abapSap700 (including)700 (including)
Netweaver_application_server_abapSap701 (including)701 (including)
Netweaver_application_server_abapSap702 (including)702 (including)
Netweaver_application_server_abapSap710 (including)710 (including)
Netweaver_application_server_abapSap711 (including)711 (including)
Netweaver_application_server_abapSap731 (including)731 (including)
Netweaver_application_server_abapSap740 (including)740 (including)
Netweaver_application_server_abapSap750 (including)750 (including)
Netweaver_application_server_abapSap751 (including)751 (including)
Netweaver_application_server_abapSap753 (including)753 (including)
Netweaver_application_server_abapSap755 (including)755 (including)

References