Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6371 Information disclosure in SAP NetWeaver AS ABAP via the POWL Test Feeder endpoint, SAP security note 2963137

SAP Note 2963137

SAP security note 2963137, "[CVE-2020-6371] Information Disclosure in SAP NetWeaver AS ABAP via the POWL Test Feeder Endpoint". Below are the symptom and SAP recommended solution.

Description

Symptom

A user enumeration vulnerability can be exploited to obtain a list of user accounts, and personal user information may be exposed in the POWL test application.

Impact of Information Disclosure:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

Implement the correction instructions below to mitigate the vulnerability and prevent users from accessing information related to other user accounts.

This issue was never exploitable within productive Cloud products hosted by SAP, such as SAP S/4HANA Cloud Edition.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Full note on SAP: SAP Support Launchpad note 2963137

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More