Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26818 Multiple vulnerabilities in SAP NetWeaver AS ABAP (Web Dynpro), SAP security note 2971954

SAP Note 2971954

SAP security note 2971954, "[CVE-2020-26818] Multiple vulnerabilities in SAP NetWeaver AS ABAP (Web Dynpro)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Information Disclosure (CVE-2020-26818): SAP NetWeaver AS ABAP allows an authenticated user access to WebDynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users, resulting in information disclosure.

Improper Access Control (CVE-2020-26819): SAP NetWeaver AS ABAP allows an authenticated user access to WebDynpro components, enabling them to read and modify database logfiles.

Solution

Additional authorization checks have been added for every subapplication.

Remark: The affected transaction is not relevant in a Cloud Solution.

Reason and prerequisites

Authorization check is only performed for the main application, not for the subpages.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected components

  • SAP_BW 731
  • SAP_BW 740
  • SAP_BW 750 to 755
  • SAP_BW 782

Full note on SAP: SAP Support Launchpad note 2971954

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More