Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-26820 Privilege escalation in SAP NetWeaver Application Server for Java (UDDI Server), SAP security note 2979062

SAP Note 2979062
SAP Security Note
HotNews

SAP security note 2979062, “[CVE-2020-26820] Privilege escalation in SAP NetWeaver Application Server for Java (UDDI Server)”, is a program error note released on 22.12.2020. Below are the symptom and the SAP recommended solution.

ComponentBasis Components > Enterprise Service Infrastructure > UDDI Server
CategoryProgram error
PriorityHotNews
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on22.12.2020
LanguageEnglish

Description

Symptom

Update 22nd December 2020: This note has been re-released with updated Support Packages & Patches information. We have provided the fix to the version SR UI 7.40 SP 017 & SR UI 7.31 SP 022.

The UDDI Server of SAP NetWeaver Application Server for Java allows an attacker to execute arbitrary OS commands without having the required permissions, known as a privilege escalation vulnerability. The potential impact includes a total compromise of confidentiality, integrity, and availability of the server OS.

Solution

Arbitrary OS command execution is now prevented by the prefer list approach. Deploy the Support Packages and Patches referenced by this SAP Security Note.

Reason and prerequisites

To exploit this vulnerability, an attacker would need access to NetWeaver Administrator (NWA) and requires NWA_SUPERADMIN permissions. The vulnerability is caused by a code error.

CVSS

Score 9.1 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Full note on SAP: SAP Support Launchpad note 2979062

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More