LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-6287: SAP NetWeaver Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-6287 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create…

CVE-2020-6287 is a missing-authentication flaw in SAP NetWeaver Application Server Java Platforms. An unauthenticated attacker can reach critical configuration functions and create administrative users. Because those actions grant high privilege inside the application stack, the issue matters for any organization running SAP NetWeaver Java components that are reachable from untrusted networks.

Public detail is limited to the CISA description and the CWE classification; exact affected releases, CVSS scores, and exploit mechanics must be confirmed against the vendor advisory.

How it works

The weakness is CWE-306: Missing Authentication for Critical Function. In this class of flaw, a sensitive operation is exposed without first verifying the caller’s identity or authorization. According to the CISA summary, the vulnerable SAP NetWeaver Application Server Java Platforms allow unauthenticated access to execute configuration tasks and to create administrative users.

An attacker who can reach the affected interface can therefore invoke those tasks directly. Successful abuse typically yields a new administrative account under the attacker’s control, after which the attacker can alter system configuration, deploy additional components, or move laterally inside the SAP landscape. No further exploit specifics are provided in the available facts; defenders should treat any unauthenticated call that results in user creation or configuration change as a potential indicator and validate behavior against the vendor advisory.

Am I affected? How to find it in your systems

SAP NetWeaver Application Server Java commonly underpins SAP business applications, portals, and integration scenarios. It is often deployed on dedicated application servers or as part of larger SAP landscapes, sometimes exposed through reverse proxies or load balancers.

Any system that matches the vendor’s affected criteria and exposes the critical functions without authentication should be treated as vulnerable until patched or otherwise mitigated.

How to remediate

The primary remediation is to apply the updates supplied by SAP, following the instructions in the vendor advisory for CVE-2020-6287. CISA’s required action is simply “Apply updates per vendor instructions.”

If you can't patch immediately

When immediate patching is not feasible, apply compensating controls that reduce exposure of the unauthenticated critical functions.

These measures do not eliminate the vulnerability; they only lower the likelihood of successful exploitation until the vendor update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to full administrative compromise of the SAP system and subsequent exposure of business data. Known ransomware use is not documented for this CVE. If you suspect compromise, follow your incident-response plan: isolate affected hosts, preserve logs, rotate credentials for any newly created or potentially stolen administrative accounts, and assess whether sensitive data left the environment. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated credentials have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · NetWeaver
WeaknessCWE-306
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities