
Cloud Vulnerability DB
A community-led vulnerabilities database
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50, contains a critical vulnerability (CVE-2020-26829) discovered in 2020. The vulnerability stems from missing authentication checks in the cluster communication system, which allows arbitrary connections from processes outside the cluster and network segment dedicated for internal cluster communication (NVD).
The vulnerability exists in the Cluster Manager component introduced in SAP AS Java since version 7.10. The Cluster Manager listens by default on all interfaces on TCP ports following the pattern 50000+100i+20+5n, where 'i' refers to the JAVA instance number and 'n' is the node number within the cluster. The vulnerability has received a CVSS v3.1 base score of 10.0 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating the highest severity level (SecurityWeek, Onapsis).
The vulnerability allows an unauthenticated attacker to invoke functions typically restricted to system administrators. The potential impacts include installation of new trusted SSO providers, modification of database connection parameters, access to sensitive configuration information, and the ability to shut down the system completely. This could lead to full privileged access to the affected SAP system or result in a denial-of-service condition (SecurityWeek, NVD).
The vulnerability can be exploited by an unauthenticated attacker who can reach the Cluster Manager TCP port. The attack requires no user interaction and can be executed with low attack complexity. Due to missing authentication checks, the attacker can execute highly privileged actions without authentication (Onapsis).
SAP has released security note 2974774 containing patches for the affected components. Organizations are strongly recommended to download and apply these security fixes to reduce business risks. The patches are available through the SAP Support Portal (SecurityWeek, Onapsis).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."