CVE detail
CVE-2020-6287
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
19 source links · newest first
A review of four years of threat intelligence data, presented Friday at Black Hat by Yvan Genuer, a senior security researcher at Onapsis, reports a spike in hacker interest in breaking into enterprise resource planning (ERP) systems from SAP in 2020 that was sustained until the end of 2023. The vast majority (87%) of the […]
newswww.csoonline.comDec 13, 2024, 5:38 PMTargeting SAP vulnerabilities by threat actors is currently at its peak as systems compromised by ransomware incidents have grown fivefold since 2021, according to joint research by Flashpoint and Onapsis. Based on SAP threat intelligence from Onapsis Research Labs and Flashpoint Threat Intelligence Platform, the research found that multiple, unpatched application-level SAP vulnerabilities are being […]
newswww.csoonline.comApr 17, 2024, 1:00 PMUnpatched vulnerabilities, common misconfigurations and hidden flaws in custom code continue to make enterprise SAP applications a target rich environment for attackers at a time when threats like ransomware and credential theft have emerged as major concerns for organizations. A study that Onapsis conducted last year, in collaboration with SAP, found attackers are continuously targeting […]
newswww.csoonline.comSep 20, 2022, 9:00 AM- SAP applications are getting compromised by skilled attackersHelp Net Security
Newly provisioned, unprotected SAP applications in cloud environments are getting discovered and compromised in mere hours, Onapsis researchers have found, and vulnerabilities affecting them are being weaponized in less than 72 hours after SAP releases security patches. Internet-exposed systems are more likely to be exploited and compromised, but there are also threats out there that are equipped to compromise SAP systems from the inside, they noted. The attackers can then move to steal or modify … More →
newswww.helpnetsecurity.comApr 7, 2021, 2:04 PM Threat actors are constantly targeting new vulnerabilities in SAP applications within days after the availability of security patches, according to a joint report issued by SAP and Onapsis.
newswww.securityweek.comApr 6, 2021, 8:14 PMOn-premises SAP systems are targeted by threat actors within 72 hours after security patches are released, security SAP security firm Onapsis warns. According to a joint study published by Onapsis and SAP, on-premises SAP systems are targeted by threat actors within 72 hours after security patches are released. Threat actors perform reverse-engineering of the SAP […]
newssecurityaffairs.comApr 6, 2021, 5:22 PM- Intel, SAP, and Citrix release critical security updatesHelp Net Security
August 2020 Patch Tuesday was expectedly observed by Microsoft and Adobe, but many other software firms decided to push out security updates as well. Apple released iCloud for Windows updates and Google pushed out fixes to Chrome. They were followed by Intel, SAP and Citrix. Intel’s updates It’s not unusual for Intel to take advantage of a Patch Tuesday. This time they released 18 advisories. Among the fixed flaws are: DoS, Information Disclosure and EoP … More →
newswww.helpnetsecurity.comAug 12, 2020, 10:39 AM - SAP Releases August 2020 Security UpdatesSecurityWeek
SAP this week announced the release of 15 new Security Notes as part of the August 2020 SAP Security Patch Day, including some that address serious vulnerabilities in NetWeaver.
newswww.securityweek.comAug 12, 2020, 10:35 AM Onapsis on Wednesday announced the release of an open source tool that helps organizations determine if their SAP systems are vulnerable to RECON attacks and checks if they may have already been targeted.
newswww.securityweek.comJul 23, 2020, 3:26 AM- 20th July – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 20th July 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches 130 Twitter accounts have been compromised of which 45 high profile accounts were used to promote a cryptocurrency fraud that yielded more than $120K. An ad that appeared before the attack […]
vendorresearch.checkpoint.comJul 20, 2020, 4:51 PM - Week in review: Counterfeit Cisco switches, hijacked Twitter accounts, vulnerable SAP applicationsHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: New wave of attacks aiming to rope home routers into IoT botnets A Trend Micro research is warning consumers of a major new wave of attacks attempting to compromise their home routers for use in IoT botnets. High-profile Twitter accounts hijacked to push Bitcoin scam. How did it happen? The Twittersphere went into overdrive as a bunch of prominent, verified Twitter accounts … More →
newswww.helpnetsecurity.comJul 19, 2020, 9:00 AM - Experts warn of massive internet scans for SAP systems affected by RECON VulnerabilitySecurity Affairs
Hackers have been scanning the Internet for SAP systems affected by RECON vulnerability, researchers from Bad Packets warn. Researchers from Bad Packets reported that threat actors have been scanning the Internet for SAP systems affected by RECON vulnerability, , tracked as CVE-2020-6287. Immediately after a researcher released a proof-of-concept (PoC) exploit for the RECON vulnerability, […]
newssecurityaffairs.comJul 18, 2020, 2:34 PM Someone has been scanning the internet in search of SAP systems affected by the recently disclosed vulnerability dubbed RECON. The scanning activity started just as a researcher released a proof-of-concept (PoC) exploit.
newswww.securityweek.comJul 17, 2020, 11:50 AM- Critical, Wormable Bug in Windows DNS Servers Could Allow Full Infrastructure CompromiseSecurityWeek
Exploitation Would Grant Attacker Domain Administrator Rights That Could Compromise Entire Corporate Infrastructure
newswww.securityweek.comJul 15, 2020, 9:05 AM SAP released eight new Security Notes on its July 2020 Patch Day, but also included two updates to previous Patch Day Security Notes.
newswww.securityweek.comJul 15, 2020, 3:47 AMSAP users should immediately deploy a newly released patch for a critical vulnerability that could allow hackers to compromise their systems and the data they contain. The flaw is in a core component that exists by default in most SAP deployments and can be exploited remotely without the need of a username and password. Researchers […]
newswww.csoonline.comJul 14, 2020, 12:00 PMA serious vulnerability that could impact thousands of organizations can allow hackers to take complete control of SAP systems.
newswww.securityweek.comJul 14, 2020, 11:12 AMSAP has issued patches to fix a critical vulnerability (CVE-2020-6287) that can lead to total compromise of vulnerable SAP installations by a remote, unauthenticated attacker. The flaw affects a variety of SAP business solutions, including SAP Enterprise Resource Planning (ERP), SAP Supply Chain Management (SCM), SAP HR Portal, and others. About the vulnerability (CVE-2020-6287) Discovered and reported by Onapsis researchers and dubbed RECON (which stands for Remotely Exploitable Code On NetWeaver), CVE-2020-6287 is due to … More →
newswww.helpnetsecurity.comJul 14, 2020, 10:41 AMIT giant SAP addressed a critical flaw, tracked as CVE-2020-6287 and dubbed RECON, that could allow attackers to take over corporate servers. SAP has released security patches to address a critical vulnerability, tracked as CVE-2020-6287 and dubbed RECON (Remotely Exploitable Code On NetWeaver), that could be exploited by attackers to take over corporate servers. The […]
newssecurityaffairs.comJul 14, 2020, 10:07 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-42926CVSS 5.3 · Medium
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully expl…
- CVE-2023-24526CVSS 5.3 · Medium
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in…
- CVE-2020-26829CVSS 10.0 · Critical
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication che…
- CVE-2020-6309CVSS 7.5 · High
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web servi…
- CVE-2020-6263CVSS 9.8 · Critical
Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; CORE-TOOLS 7.00, 7.01,…
- CVE-2010-5326CVSS 10.0 · Critical
The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary co…