CISA KEV 정보
| 취약점명 | SAP NetWeaver Missing Authentication for Critical Function Vulnerability |
|---|---|
| 설명 | SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. |
| 조치사항 | Apply updates per vendor instructions. |
| 랜섬웨어 캠페인 악용 | Unknown |
| CWE | CWE-306 |
| 등록일 (KEV) | 2021-11-03 |
| 조치 기한 | 2022-05-03 |
| 추가 참고 | https://nvd.nist.gov/vuln/detail/CVE-2020-6287 |
NVD 상세 정보
CVSS v3.1: 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS v3.0: 10.0 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS v2.0: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C설명: SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
CWE: CWE-306 | CWE-306
참조
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.html [Third Party Advisory, VDB Entry]
- http://seclists.org/fulldisclosure/2021/Apr/6 [Mailing List, Third Party Advisory]
- https://launchpad.support.sap.com/#/notes/2934135 [Permissions Required, Vendor Advisory]
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675 [Broken Link, Vendor Advisory]
- https://www.onapsis.com/recon-sap-cyber-security-vulnerability [Third Party Advisory]
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.html [Third Party Advisory, VDB Entry]
- http://seclists.org/fulldisclosure/2021/Apr/6 [Mailing List, Third Party Advisory]
- https://launchpad.support.sap.com/#/notes/2934135 [Permissions Required, Vendor Advisory]
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675 [Broken Link, Vendor Advisory]
- https://www.onapsis.com/recon-sap-cyber-security-vulnerability [Third Party Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6287 [US Government Resource]
This product uses the NVD API but is not endorsed or certified by the NVD.