
🔴 SAP NetWeaver #Java, Authentication Bypass, #CVE-2020-6287 (Critical) -DC-Oct2026-2733 https://dailycve.com/sap-netweaver-java-authentication-bypass-cve-2020-6287-critical-dc-oct2026-2733/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.
Priority
LOW
Exploitation
ACTIVE
PoC
NONE
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
4 versions affected across 1 product

🔴 SAP NetWeaver #Java, Authentication Bypass, #CVE-2020-6287 (Critical) -DC-Oct2026-2733 https://dailycve.com/sap-netweaver-java-authentication-bypass-cve-2020-6287-critical-dc-oct2026-2733/
4 of 4 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | sap | netweaver_application_server_java | 7.30 | - | - |
| App | sap | netweaver_application_server_java | 7.31 | - | - |
| App | sap | netweaver_application_server_java | 7.40 | - | - |
| App | sap | netweaver_application_server_java | 7.50 | - | - |