Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6299 Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform, SAP security note 2941510

SAP Note 2941510
SAP Security Note
Medium priority

SAP security note 2941510, "[CVE-2020-6299] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform", is a note released on August 10, 2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Middleware > ABAP Channels
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released onAugust 10, 2020

Description

Symptom

Under certain conditions, SAP NetWeaver ABAP Server and ABAP Platform allow an attacker to gain access to the list of all users using a vulnerable endpoint as a low-privileged user. This vulnerability can be exploited for information gathering, facilitating further exploits and attacks.

An attacker with low-level privileges can exploit this vulnerability to retrieve a list of all users in the system. This information disclosure can aid in planning more targeted attacks against user accounts.

Solution

The root cause is the unrestricted access to the user list via the ABAP Online Community application’s value help (F4 help). The solution involves removing the value help functionality from the ABAP Online Community application.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected components

  • SAP_BASIS: Versions 740 to 740, 750 to 755

Full note on SAP: SAP Support Launchpad note 2941510

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More