Risk | High |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-26829 |
CWE-ID | CWE-287 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
SAP NetWeaver Server applications / Application servers |
Vendor | SAP |
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU48818
Risk: High
CVSSv3.1:
CVE-ID: CVE-2020-26829
CWE-ID:
CWE-287 - Improper Authentication
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests within the P2P Cluster Communication component. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Successful exploitation of the vulnerability may allow an attacker to compromise the server.
Install update from vendor's website.
Vulnerable software versionsSAP NetWeaver: 7.11 - 7.31
http://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?