CVE-2020-6190

Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:*

History

21 Nov 2024, 05:35

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2838835 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/2838835 - Permissions Required, Vendor Advisory
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812 - Vendor Advisory

Information

Published : 2020-02-12 20:15

Updated : 2024-11-21 05:35


NVD link : CVE-2020-6190

Mitre link : CVE-2020-6190

CVE.ORG link : CVE-2020-6190


JSON object : View

Products Affected

sap

  • netweaver_application_server_java
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor