Back to overview

CVE-2020-26829

CRITICAL
10.0
CVSS 3.0
Description
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only, including access to system administration functions or shutting down the system completely.

Metadata

CVE ID
CVE-2020-26829
State
PUBLISHED
Assigner
sap
Reserved
2020-10-07 00:00 UTC
Published
2020-12-09 16:28 UTC
Last updated
2024-08-04 16:03 UTC
Vendor / Product
SAP SE / SAP NetWeaver AS JAVA (P2P Cluster Communication)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
SAP SE SAP NetWeaver AS JAVA (P2P Cluster Communication) < 7.11, < 7.20, < 7.30, < 7.31 …
Weakness (CWE)
CWESourceDescription
cna Missing Authentication Check
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview