#VU29717 Input validation error

Published: 2020-07-15 | Updated: 2020-09-01

Vulnerability identifier: #VU29717

Vulnerability risk: High

CVSSv3.1: 8.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2020-6286


Exploitation vector: Network

Exploit availability: Yes

Vulnerable software:
SAP NetWeaver
Server applications / Application servers

Vendor: SAP


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to unspecified error in the LM Configuration Wizard component. A remote attacker can execute arbitrary code on the target system.

Install updates from vendor's website.

Vulnerable software versions

SAP NetWeaver: 7.30 - 7.50


External links

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

Latest bulletins with this vulnerability