Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6224 Information Disclosure in SAP NetWeaver Application Server Java (HTTP Service), SAP security note 2826528

SAP Note 2826528

SAP security note 2826528, “[CVE-2020-6224] Information Disclosure in SAP NetWeaver Application Server Java (HTTP Service)”, is released on 22.12.2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-JAS-WEB (Basis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets)
Version7
StatusReleased for Customer
Released on22.12.2020

Description

Symptom

Under certain conditions, SAP NetWeaver AS Java allows an attacker with administrative privileges to access sensitive information, including user passwords in trace files. This vulnerability occurs when a user logs in and sends a request with login credentials, leading to potential information disclosure.

Impacts of information disclosure include:

  • Loss of information and system configuration confidentiality
  • Information gathering for further exploits and attacks

Solution

Update your SAP NetWeaver Application Server Java to a support package or release where the issue is fixed. The affected system no longer reveals internal information and user sensitive data post-update. Refer to the Support Packages & Patches section of this SAP Note for detailed information and available patches.

CVSS

Score 6.2 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

References

  • CVE-2020-6224

Affected components

  • BC-JAS-WEB (Basis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets)

Full note on SAP: SAP Support Launchpad note 2826528

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More