CVE-2020-6224 Information
Feb 14, 2021
cve
Description
SAP NetWeaver AS Java (HTTP Service) versions 7.10 7.11 7.20 7.30 7.31 7.40 7.50 allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files when the user logs in and sends request with login credentials leading to Information Disclosure.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
Reference
https://launchpad.support.sap.com//notes/2826528 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.2
Share on: