CVE-2020-6287

10.0 CRITICAL CISA KEV - Actively Exploited
Published: July 14, 2020 Modified: October 31, 2025

Description

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://seclists.org/fulldisclosure/2021/Apr/6
Source: cna@sap.com
Mailing List Third Party Advisory
https://launchpad.support.sap.com/#/notes/2934135
Source: cna@sap.com
Permissions Required Vendor Advisory
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675
Source: cna@sap.com
Broken Link Vendor Advisory
http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2021/Apr/6
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
https://launchpad.support.sap.com/#/notes/2934135
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required Vendor Advisory
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Vendor Advisory
https://www.onapsis.com/recon-sap-cyber-security-vulnerability
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6287
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

11 reference(s) from NVD

Quick Stats

CVSS v3 Score
10.0 / 10.0
EPSS (Exploit Probability)
94.4%
100th percentile
Exploitation Status
Actively Exploited
Remediation due: 2022-05-03

Weaknesses (CWE)

Affected Vendors

sap