VYPR
Unrated severityNVD Advisory· Published Apr 14, 2020· Updated Aug 4, 2024

CVE-2020-6224

CVE-2020-6224

Description

SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.

Affected products

2
  • Range: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
  • SAP SE/SAP NetWeaver AS Java (HTTP Service)v5
    Range: < 7.10

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.