Vulnerability Details CVE-2020-6285
SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.9%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 3.5
Products affected by CVE-2020-6285
-
cpe:2.3:a:sap:netweaver:7.10
-
cpe:2.3:a:sap:netweaver:7.11
-
cpe:2.3:a:sap:netweaver:7.20
-
cpe:2.3:a:sap:netweaver:7.30
-
cpe:2.3:a:sap:netweaver:7.31
-
cpe:2.3:a:sap:netweaver:7.40
-
cpe:2.3:a:sap:netweaver:7.50