Vulnerability Description
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver Application Server Abap | 731 |
References
- https://launchpad.support.sap.com/#/notes/2971954Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2971954Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
FAQ
What is CVE-2020-26819?
CVE-2020-26819 is a vulnerability with a CVSS score of 8.8 (HIGH). SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database l...
How severe is CVE-2020-26819?
CVE-2020-26819 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26819?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver Application Server Abap.