CVE-2020-6299

Description

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.226

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 740Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAPWindows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 751Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 753Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 754Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 755Windows
Multiple Vulnerabilities are affected in SAP ABAP Platform (ABAP Build Framework) 740Windows
Multiple Vulnerabilities are affected in SAP ABAP Platform (ABAP Build Framework) 750Windows
Multiple Vulnerabilities are affected in SAP ABAP Platform (ABAP Build Framework) 751Windows
Multiple Vulnerabilities are affected in SAP ABAP Platform (ABAP Build Framework) 753Windows
Multiple Vulnerabilities are affected in SAP ABAP Platform (ABAP Build Framework) 755Windows
Vulnerabilities CVE-2020-6299,CVE-2020-6318,CVE-2021-44231,CVE-2023-25615 are affected in SAP ABAP Platform (ABAP Build Framework) 754Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 740Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 750Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 751Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 753Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 754Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 755Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234