CVE-2020-6310

Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:abap_platform:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:7.40:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:7.50:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:755:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-08-12 14:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-6310

Mitre link : CVE-2020-6310

CVE.ORG link : CVE-2020-6310


JSON object : View

Products Affected

sap

  • netweaver_application_server_abap
  • abap_platform