Medium severity5.8NVD Advisory· Published Feb 12, 2020· Updated Jun 17, 2026
CVE-2020-6190
CVE-2020-6190
Description
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.
Affected products
6- SAP SE/SAP NetWeaver AS Java (Heap Dump Application)v5Range: = 7.30
- Range: 7.30, 7.31, 7.40, 7.50
cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:sap:netweaver_application_server_java:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.