← back
CVE-2020-26829critical

CVE-2020-26829

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 10epss 4.7%
exploitation probability
4.7%top 9% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only, including access to system administration functions or shutting down the system completely.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.