Low severity2.7NVD Advisory· Published Jul 14, 2020· Updated Jun 17, 2026
CVE-2020-6280
CVE-2020-6280
Description
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
Affected products
9cpe:2.3:a:sap:abap_platform:7.31:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:sap:abap_platform:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:abap_platform:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:abap_platform:7.50:*:*:*:*:*:*:*
- (no CPE)
cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:*
- SAP SE/SAP NetWeaver (ABAP Server) and ABAP Platformv5Range: < 731
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.