S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-6287 Scanner

CVE-2020-6287 scanner - Improper Access Control vulnerability in SAP NetWeaver Application Server

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-6287
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
SAP NetWeaver AS JAVA (LM Configuration Wizard)by SAP SE
< 7.30
Updated Aug 21, 2026View on NVD →
Detail

SAP NetWeaver Application Server (AS) JAVA is an integrated technology platform that supports the development and execution of Java-based applications in the SAP environment. It provides a range of services, including application server, portal, web services, and business process management. 

However, this product is not without its vulnerabilities. The most recent one, CVE-2020-6287, is a missing authentication check vulnerability. This vulnerability allows an attacker without prior authentication to execute configuration tasks and perform critical actions against the SAP Java system. One of these actions is creating an administrative user, which can compromise the Confidentiality, Integrity, and Availability of the system.

When this vulnerability is exploited, it can lead to serious consequences for businesses. Since an attacker can create an administrative user, they have complete control over the SAP Java system. They can access confidential information, modify or delete data, and disrupt business operations, leading to financial loss and reputational damage.

Thanks to the pro features of the s4e.io platform, businesses and individuals can easily and quickly learn about vulnerabilities in their digital assets. By subscribing to the platform, users can receive real-time alerts about new vulnerabilities and detailed risk assessments of their digital assets. This proactive approach to cybersecurity is essential in today's world, where cyberattacks are becoming increasingly sophisticated and frequent.

 

REFERENCES

Solution Advice

Organizations that use SAP NetWeaver AS JAVA can take several precautions to protect against this vulnerability, such as:

  • Apply the security note released by SAP.
  • Disable the LM Configuration Wizard.
  • Restrict access to the LM Configuration Wizard and other critical functions.
  • Implement network segmentation to isolate critical systems.
  • Monitor system logs and user activity for suspicious behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.