Critical severity9.1NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026
CVE-2020-6203
CVE-2020-6203
Description
SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.
Affected products
9cpe:2.3:a:sap:netweaver:7.10:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sap:netweaver:7.10:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.11:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.20:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.50:*:*:*:*:*:*:*
- Range: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
- SAP SE/SAP NetWeaver UDDI Server (Services Registry)v5Range: < 7.10
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.