« Volver al listado

CVE-2020-6299

Estado: ModificadaMedia (4.3)—

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-6299",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver (ABAP Server) and ABAP Platform",
          "versions": [
            {
              "status": "affected",
              "version": "< 740"
            },
            {
              "status": "affected",
              "version": "< 750"
            },
            {
              "status": "affected",
              "version": "< 751"
            },
            {
              "status": "affected",
              "version": "< 752"
            },
            {
              "status": "affected",
              "version": "< 753"
            },
            {
              "status": "affected",
              "version": "< 754"
            },
            {
              "status": "affected",
              "version": "< 755"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-08-12T14:15:14.423",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2941510",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2941510",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure."
    },
    {
      "lang": "es",
      "value": "SAP NetWeaver (ABAP Server) y la plataforma ABAP, versiones - 740, 750, 751, 752, 753, 754, 755, permiten a un usuario empresarial acceder a la lista de usuarios en el sistema dado usando la ayuda de valor, conllevando a una Divulgación de Información"
    }
  ],
  "lastModified": "2026-06-17T03:23:01.603",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:abap_platform:740:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07710B18-BF01-4316-A258-4F1CB6269C5E"
            },
            {
              "criteria": "cpe:2.3:a:sap:abap_platform:750:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3A631DA-1279-49AC-922E-7D7216DACC8D"
            },
            {
              "criteria": "cpe:2.3:a:sap:abap_platform:751:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65320F25-669B-40D8-A246-07B0202C00A9"
            },
            {
              "criteria": "cpe:2.3:a:sap:abap_platform:753:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1C86F45-445E-4970-A378-199A35B23F4B"
            },
            {
              "criteria": "cpe:2.3:a:sap:abap_platform:754:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74901A8A-A556-478F-ABCD-7DCFD471210A"
            },
            {
              "criteria": "cpe:2.3:a:sap:abap_platform:755:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B48E0FF-814F-4F9C-B5B1-87D978E1B4A4"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "127E508F-6CC1-41C8-96DF-8D14FFDD4020"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7777AA80-1608-420E-B7D5-09ABECD51728"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:751:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0539618A-1C4D-463F-B2BB-DD1C239C23EB"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:753:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9F38585-73AE-4DBB-A978-F0272DF8FB58"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:754:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D416C064-BB8A-4230-A761-84A93E017F79"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_application_server_abap:755:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B8D3EA0-28E6-4333-8C67-B9D3775EB9BC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}