Unrated severityNVD Advisory· Published Nov 10, 2020· Updated Aug 4, 2024
CVE-2020-26820
CVE-2020-26820
Description
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 7.20, 7.30, 7.31, 7.40, 7.50
- SAP SE/SAP NetWeaver AS JAVAv5Range: < 7.20
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/162086/SAP-Java-OS-Remote-Code-Execution.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2021/Apr/7mitremailing-listx_refsource_FULLDISC
- launchpad.support.sap.commitrex_refsource_MISC
- wiki.scn.sap.com/wiki/pages/viewpage.actionmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.