Vulnerability Description
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Abap Platform | 7.31 |
| Sap | Netweaver Application Server Abap | 731 |
References
- https://launchpad.support.sap.com/#/notes/2927373Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2927373Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675Vendor Advisory
FAQ
What is CVE-2020-6280?
CVE-2020-6280 is a vulnerability with a CVSS score of 2.7 (LOW). SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Dis...
How severe is CVE-2020-6280?
CVE-2020-6280 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6280?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Abap Platform, Sap Netweaver Application Server Abap.