VDB

CVE-2020-26829

CVE-2020-26829 PUBLISHED CVSS 10 CRITICAL

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only, including access to system administration functions or shutting down the system completely.

EPSS 3.95% · 88.5th percentile

Risk Scores

CVSS v3.0
10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
3.95%
88.5th percentile

Affected Products

VendorProductVersions
sapnetweaver_application_server_java7.30, 7.11, 7.20
SAP SESAP NetWeaver AS JAVA (P2P Cluster Communication)< 7.11, < 7.30, < 7.31

Timeline

  • Dec 8, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 19, 2021 EPSS Score
  • Jun 24, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›