SAP security note 2971954, "[CVE-2020-26818] Multiple vulnerabilities in SAP NetWeaver AS ABAP (Web Dynpro)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Information Disclosure (CVE-2020-26818): SAP NetWeaver AS ABAP allows an authenticated user access to WebDynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users, resulting in information disclosure.
Improper Access Control (CVE-2020-26819): SAP NetWeaver AS ABAP allows an authenticated user access to WebDynpro components, enabling them to read and modify database logfiles.
Solution
Additional authorization checks have been added for every subapplication.
Remark: The affected transaction is not relevant in a Cloud Solution.
Reason and prerequisites
Authorization check is only performed for the main application, not for the subpages.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected components
- SAP_BW 731
- SAP_BW 740
- SAP_BW 750 to 755
- SAP_BW 782
Full note on SAP: SAP Support Launchpad note 2971954
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
