Sploitus

CVE-2020-6286

3 known exploits for CVE-2020-6286

The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method to download zip files to a specific directory, leading to Path Traversal.

Affected products
Sap Netweaver As Java
Sap Netweaver Application Server Java
= 7.30, 7.31, 7.40, 7.50
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
28.3% (98th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2020-07-14
CVE-2020-6286 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2020-6286

Proof-of-concept code and exploit modules indexed by Sploitus