Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6285 Information Disclosure in SAP NetWeaver (XMLToolkit for Java), SAP security note 2932473

SAP Note 2932473

SAP security note 2932473, “[CVE-2020-6285] Information Disclosure in SAP NetWeaver (XMLToolkit for Java)”. Below are the symptom and SAP recommended solution.

Description

Symptom

Under certain conditions SAP XML Toolkit for Java allows an attacker to access arbitrary files which would otherwise be restricted.

Some well-known impacts of Information Disclosure are:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

This issue is fixed in the patches listed in the Support Packages & Patches section below.

Reason and prerequisites

SAPXMLToolkit is used as a parser.

CVSS

Score 7.7 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2932473

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More