Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01, 7.02, 7.05, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not perform any authentication checks for operations that require user identity leading to Authentication Bypass.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2878568 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: sap
Published: 2020-06-10T12:44:43
Updated: 2020-06-10T12:44:43
Reserved: 2020-01-08T00:00:00
Link: CVE-2020-6263
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-06-10T13:15:18.010
Modified: 2021-07-21T11:39:23.747
Link: CVE-2020-6263
JSON object: View
Redhat Information
No data.
CWE