SAP Security Note
HotNews
SAP security note 2979062, “[CVE-2020-26820] Privilege escalation in SAP NetWeaver Application Server for Java (UDDI Server)”, is a program error note released on 22.12.2020. Below are the symptom and the SAP recommended solution.
Description
Symptom
Update 22nd December 2020: This note has been re-released with updated Support Packages & Patches information. We have provided the fix to the version SR UI 7.40 SP 017 & SR UI 7.31 SP 022.
The UDDI Server of SAP NetWeaver Application Server for Java allows an attacker to execute arbitrary OS commands without having the required permissions, known as a privilege escalation vulnerability. The potential impact includes a total compromise of confidentiality, integrity, and availability of the server OS.
Solution
Arbitrary OS command execution is now prevented by the prefer list approach. Deploy the Support Packages and Patches referenced by this SAP Security Note.
Reason and prerequisites
To exploit this vulnerability, an attacker would need access to NetWeaver Administrator (NWA) and requires NWA_SUPERADMIN permissions. The vulnerability is caused by a code error.
CVSS
Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Full note on SAP: SAP Support Launchpad note 2979062
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



