Files
CVEs-PoC/2020/CVE-2020-26818.md
T
2024-05-25 21:48:12 +02:00

18 lines
857 B
Markdown

### [CVE-2020-26818](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26818)
![](https://img.shields.io/static/v1?label=Product&message=SAP%20NetWeaver%20AS%20ABAP%20(Web%20Dynpro)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C731%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Information%20Disclosure&color=brighgreen)
### Description
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/Live-Hack-CVE/CVE-2020-26818