VDB

CNVD-2020-38866

CNVD-2020-38866 PUBLISHED CVSS 10 CRITICAL

SAP Netweaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。SAP NetWeaver Application Server(AS)Java是一款运行于NetWeaver中且基于Java编程语言的应用服务器。 SAP NetWeaver AS Java(LM配置向导)7.30至7.50版本存在安全漏洞。未经身份验证的远程攻击者可以通过创建具有最大特权的新SAP用户,绕过所有访问和授权控制,从而完全控制SAP系统。

Risk Scores

CVSS 3.0
10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
SAP SESAP NetWeaver AS JAVA (LM Configuration Wizard)< 7.30, < 7.31, < 7.50

Timeline

  • Apr 17, 2019 CVE Published
  • Jul 23, 2020 PoC Published
  • Nov 8, 2021 PoC Published
  • Nov 20, 2021 PoC Published
  • Nov 14, 2024 PoC Published
  • Dec 24, 2024 PoC Published
  • Jan 12, 2025 PoC Published
  • Jan 26, 2025 PoC Published
  • Feb 6, 2025 PoC Published
  • Feb 23, 2025 PoC Published
  • Feb 23, 2025 PoC Published
  • Jun 5, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›