VYPR
Unrated severityNVD Advisory· Published Nov 10, 2020· Updated Aug 4, 2024

CVE-2020-26820

CVE-2020-26820

Description

SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Range: 7.20, 7.30, 7.31, 7.40, 7.50
  • SAP SE/SAP NetWeaver AS JAVAv5
    Range: < 7.20

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.