CVE-2020-6286
SAP NetWeaver Application Server Java vulnerability analysis and mitigation

Overview

The SAP NetWeaver AS JAVA vulnerability (CVE-2020-6286), also known as RECON, was discovered in early 2020. This critical vulnerability affects the LM Configuration Wizard component in SAP NetWeaver AS JAVA versions 7.30, 7.31, 7.40, and 7.50. The flaw allows unauthenticated attackers to exploit a method to download zip files to specific directories, leading to path traversal issues (CERT-EU, NVD).

Technical details

The vulnerability stems from insufficient input path validation of certain parameters in the web service of SAP NetWeaver AS JAVA's LM Configuration Wizard. It received a critical CVSS score of 10.0, indicating maximum severity. The flaw affects a default component present in every SAP application running the SAP NetWeaver Java technology stack, including SAP S/4HANA Java, SAP SCM, SAP CRM, SAP Enterprise Portal, and SAP Solution Manager (CERT-EU).

Impact

If successfully exploited, the vulnerability allows attackers to obtain unrestricted access to SAP systems through the creation of high-privileged users. The attacker can execute arbitrary operating system commands with the privileges of the SAP service user account (adm), which has unrestricted access to the SAP database and can perform application maintenance activities (CERT-EU).

Exploitability

Proof-of-concept exploit code became publicly available within days of the vulnerability's disclosure, and active scanning for vulnerable systems was observed in the wild. The vulnerability requires no authentication to exploit, making it particularly dangerous (BleepingComputer).

Mitigation and workarounds

SAP released security patches to address this vulnerability through Security Note #2934135. Given the critical nature of the vulnerability and the availability of public exploits, immediate patching was strongly recommended for affected systems (CERT-EU).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-42944CRITICAL10
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesSep 09, 2025
CVE-2026-40128CRITICAL9
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesJun 09, 2026
CVE-2026-27674MEDIUM6.1
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesApr 14, 2026
CVE-2025-42926MEDIUM5.3
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesSep 09, 2025
CVE-2026-23686LOW3.4
  • SAP NetWeaver Application Server Java logoSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management