SAP Security Note
Medium priority
SAP security note 2941510, "[CVE-2020-6299] Information Disclosure in SAP NetWeaver (ABAP Server) and ABAP Platform", is a note released on August 10, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, SAP NetWeaver ABAP Server and ABAP Platform allow an attacker to gain access to the list of all users using a vulnerable endpoint as a low-privileged user. This vulnerability can be exploited for information gathering, facilitating further exploits and attacks.
An attacker with low-level privileges can exploit this vulnerability to retrieve a list of all users in the system. This information disclosure can aid in planning more targeted attacks against user accounts.
Solution
The root cause is the unrestricted access to the user list via the ABAP Online Community application’s value help (F4 help). The solution involves removing the value help functionality from the ABAP Online Community application.
CVSS
Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected components
- SAP_BASIS: Versions 740 to 740, 750 to 755
Full note on SAP: SAP Support Launchpad note 2941510
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



