CVE-2020-6310
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
Published
2020-08-12T14:15:14.767
Last Modified
2024-11-21T05:35:29.030
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 4.3 (MEDIUM)
CVSSv2 Vector
AV:N/AC:L/Au:S/C:P/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: SINGLE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
8.0
Impact Score
2.9
Weaknesses
-
Type: Primary
NVD-CWE-noinfo
Affected Vendors & Products
References