MEDIUM
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure
Published Aug 12, 2020
4.3
MEDIUMCVSS 3.1
EPSS 0.94%
Description
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
Affected products
-
- Version < 702StatusaffectedConstraints-
- Version < 730StatusaffectedConstraints-
- Version < 731StatusaffectedConstraints-
- Version < 740StatusaffectedConstraints-
- Version < 750StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SAP SE | SAP NetWeaver (ABAP Server) and ABAP Platform | n/a |
|
OR
- 7.31
- 7.40
- 7.50
- 700
- 701
- 702
- 710
- 711
- 751
- 753
- 755
- 700
- 701
- 702
- 710
- 711
- 731
- 740
- 750
- 751
- 753
- 755
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27460 Advisory
- https://launchpad.support.sap.com/#/notes/2944988 x_refsource_MISCPermissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27460 | Advisory | |
| https://launchpad.support.sap.com/#/notes/2944988 | x_refsource_MISCPermissions Required | |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner sap
Published Aug 12, 2020
Updated Aug 4, 2024
Reserved Jan 8, 2020
Link CVE-2020-6310
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-27460 Assigner sap
Published Aug 12, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-27460