Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6190Information Disclosure in SAP NetWeaver AS Java (Heap Dump Application), SAP security note 2838835

SAP Note 2838835

SAP security note 2838835, “[CVE-2020-6190] Information Disclosure in SAP NetWeaver AS Java (Heap Dump Application)”. Below are the symptom and SAP recommended solution.

Description

Symptom

SAP NetWeaver AS Java Heap Dump Application allows an attacker to exploit certain misconfigured application endpoints to read sensitive data without authentication. These endpoints are normally exposed over the network and successful exploitation can lead to exposure of data like Host Name, server Node, and the installation path that could help the attacker collect information about the NetWeaver implementation.

Solution

Update your AS Java to a Support Package (SP) or release where the issue is fixed. See the Support Package Patch Level section for details and available patches.

The solution disables the Heap Dump Application so that it is not started and not accessible anymore. You may use some offline tool for Heap Dump Analysis.

Reason and prerequisites

Any information can be seen only if the system had heap dump analysis performed on it.

CVSS

Score 5.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Full note on SAP: SAP Support Launchpad note 2838835

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More