CVE-2020-6371
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/10/2020
Last modified:
05/10/2022
Description
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:netweaver_application_server_abap:710:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:711:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:730:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:731:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



