Security Advisory

CVE-2020-6224

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-04-14 18:31:46
Last updated 2024-08-04 08:55:22
Assigner sap
State PUBLISHED

Description

SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.