CVE-2020-26818
CVE-2020-26818
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 nov 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Productos afectados
SAP SE · SAP NetWeaver AS ABAP (Web Dynpro)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →