4.3
CVE-2020-6310
- EPSS 0.94%
- Veröffentlicht 12.08.2020 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:29
- Erkennungen
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Abap Platform Version 7.31
SAP ≫ Abap Platform Version 7.40
SAP ≫ Abap Platform Version 7.50
SAP ≫ Abap Platform Version 700
SAP ≫ Abap Platform Version 701
SAP ≫ Abap Platform Version 702
SAP ≫ Abap Platform Version 710
SAP ≫ Abap Platform Version 711
SAP ≫ Abap Platform Version 751
SAP ≫ Abap Platform Version 753
SAP ≫ Abap Platform Version 755
SAP ≫ Netweaver Application Server Abap Version 700
SAP ≫ Netweaver Application Server Abap Version 701
SAP ≫ Netweaver Application Server Abap Version 702
SAP ≫ Netweaver Application Server Abap Version 710
SAP ≫ Netweaver Application Server Abap Version 711
SAP ≫ Netweaver Application Server Abap Version 731
SAP ≫ Netweaver Application Server Abap Version 740
SAP ≫ Netweaver Application Server Abap Version 750
SAP ≫ Netweaver Application Server Abap Version 751
SAP ≫ Netweaver Application Server Abap Version 753
SAP ≫ Netweaver Application Server Abap Version 755
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.94% | 0.562 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| SAP | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345
https://launchpad.support.sap.com/#/notes/2944988