CVE-2020-6310 is an improper access control vulnerability in the SOA Configuration Trace component of SAP NetWeaver (ABAP Server) and ABAP Platform, affecting versions 702 through 750. This flaw allows any authenticated user to enumerate all SAP users, resulting in information disclosure. With a CVSS score of 4.3 (Medium), the vulnerability has a low attack complexity and requires local authentication, but does not impact integrity or availability. The primary impact is limited confidentiality, specifically the exposure of user lists. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, indicating low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.31CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.31:*:*:*:*:*:*:* | ||
7.40CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.40:*:*:*:*:*:*:* | ||
7.50CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:7.50:*:*:*:*:*:*:* | ||
700CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:700:*:*:*:*:*:*:* | ||
701CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:701:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.