ID

VAR-202003-1737


CVE

CVE-2020-6203


TITLE

SAP NetWeaver UDDI Server Past Traversal Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-002739

DESCRIPTION

SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal. SAP NetWeaver UDDI Server (Services Registry) Exists in a past traversal vulnerability.Information may be obtained and tampered with

Trust: 1.62

sources: NVD: CVE-2020-6203 // JVNDB: JVNDB-2020-002739

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:7.10

Trust: 1.8

vendor:sapmodel:netweaverscope:eqversion:7.11

Trust: 1.8

vendor:sapmodel:netweaverscope:eqversion:7.20

Trust: 1.8

vendor:sapmodel:netweaverscope:eqversion:7.30

Trust: 1.8

vendor:sapmodel:netweaverscope:eqversion:7.31

Trust: 1.8

vendor:sapmodel:netweaverscope:eqversion:7.40

Trust: 1.8

vendor:sapmodel:netweaverscope:eqversion:7.50

Trust: 1.8

sources: JVNDB: JVNDB-2020-002739 // NVD: CVE-2020-6203

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-6203
value: CRITICAL

Trust: 1.0

cna@sap.com: CVE-2020-6203
value: CRITICAL

Trust: 1.0

NVD: JVNDB-2020-002739
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202003-588
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2020-6203
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-002739
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-6203
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 5.2
version: 3.1

Trust: 1.0

cna@sap.com: CVE-2020-6203
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.3
impactScore: 6.0
version: 3.0

Trust: 1.0

NVD: JVNDB-2020-002739
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-002739 // CNNVD: CNNVD-202003-588 // NVD: CVE-2020-6203 // NVD: CVE-2020-6203

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.8

sources: JVNDB: JVNDB-2020-002739 // NVD: CVE-2020-6203

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202003-588

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-202003-588

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-002739

PATCH

title:SAP Security Patch Day - March 2020url:https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305

Trust: 0.8

title:SAP NetWeaver UDDI Server Repair measures for path traversal vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=112017

Trust: 0.6

sources: JVNDB: JVNDB-2020-002739 // CNNVD: CNNVD-202003-588

EXTERNAL IDS

db:NVDid:CVE-2020-6203

Trust: 2.4

db:JVNDBid:JVNDB-2020-002739

Trust: 0.8

db:CNNVDid:CNNVD-202003-588

Trust: 0.6

sources: JVNDB: JVNDB-2020-002739 // CNNVD: CNNVD-202003-588 // NVD: CVE-2020-6203

REFERENCES

url:https://launchpad.support.sap.com/#/notes/2806198

Trust: 1.6

url:https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageid=540935305

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-6203

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-6203

Trust: 0.8

sources: JVNDB: JVNDB-2020-002739 // CNNVD: CNNVD-202003-588 // NVD: CVE-2020-6203

SOURCES

db:JVNDBid:JVNDB-2020-002739
db:CNNVDid:CNNVD-202003-588
db:NVDid:CVE-2020-6203

LAST UPDATE DATE

2024-11-23T22:41:08.434000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-002739date:2020-03-25T00:00:00
db:CNNVDid:CNNVD-202003-588date:2020-03-17T00:00:00
db:NVDid:CVE-2020-6203date:2024-11-21T05:35:17.523

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-002739date:2020-03-25T00:00:00
db:CNNVDid:CNNVD-202003-588date:2020-03-10T00:00:00
db:NVDid:CVE-2020-6203date:2020-03-10T21:15:14.417