CVE-2020-26829 Information
Description
SAP NetWeaver AS JAVA (P2P Cluster Communication) versions - 7.11 7.20 7.30 7.31 7.40 7.50 allows arbitrary connections from processes because of missing authentication check that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only including access to system administration functions or shutting down the system completely.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Reference
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079 https://launchpad.support.sap.com/#/notes/2974774 http://seclists.org/fulldisclosure/2021/Jun/33 http://packetstormsecurity.com/files/163166/SAP-Netweaver-JAVA-7.50-Missing-Authorization.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
10.0
Share on: