High severity7.2NVD Advisory· Published Nov 10, 2020· Updated Jun 17, 2026
CVE-2020-26820
CVE-2020-26820
Description
SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- SAP SE/SAP NetWeaver AS JAVAv5Range: < 7.20
cpe:2.3:a:sap:netweaver_application_server_java:7.20:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:sap:netweaver_application_server_java:7.20:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:*
- Range: 7.20, 7.30, 7.31, 7.40, 7.50
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/162086/SAP-Java-OS-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2021/Apr/7nvdMailing ListThird Party Advisory
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.