SAP security note 2826528, “[CVE-2020-6224] Information Disclosure in SAP NetWeaver Application Server Java (HTTP Service)”, is released on 22.12.2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Under certain conditions, SAP NetWeaver AS Java allows an attacker with administrative privileges to access sensitive information, including user passwords in trace files. This vulnerability occurs when a user logs in and sends a request with login credentials, leading to potential information disclosure.
Impacts of information disclosure include:
- Loss of information and system configuration confidentiality
- Information gathering for further exploits and attacks
Solution
Update your SAP NetWeaver Application Server Java to a support package or release where the issue is fixed. The affected system no longer reveals internal information and user sensitive data post-update. Refer to the Support Packages & Patches section of this SAP Note for detailed information and available patches.
CVSS
Score 6.2 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
References
- CVE-2020-6224
Affected components
- BC-JAS-WEB (Basis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets)
Full note on SAP: SAP Support Launchpad note 2826528
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



