CVE-2020-6287
SAP NetWeaver Missing Authentication for Critical Function Vulnerability
Description
CVE-2020-6287 is a critical-severity missing authentication vulnerability in SAP NetWeaver Application Server Java, commonly known as "RECON" (Remotely Exploitable Code On NetWeaver). The LM Configuration Wizard component does not perform authentication checks, allowing unauthenticated attackers to execute configuration tasks and create administrative users on the SAP Java system. This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog with confirmed active exploitation. With an EPSS score of 94.36% (99.96th percentile), CVE-2020-6287 has a near-certain probability of exploitation, representing one of the most dangerous SAP vulnerabilities discovered.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver application server java | 7.30; 7.31; 7.40; 7.50 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/162085/SAP-JAVA-Configuration-Task-Execution.html(Third Party Advisory, VDB Entry)
- http://seclists.org/fulldisclosure/2021/Apr/6(Mailing List, Third Party Advisory)
- https://launchpad.support.sap.com/#/notes/2934135(Permissions Required, Vendor Advisory)
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552599675(Broken Link, Vendor Advisory)
- https://www.onapsis.com/recon-sap-cyber-security-vulnerability(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6287(US Government Resource)
Weakness Type
CWE-306: Missing Authentication for Critical Function
Missing Authentication for Critical Function occurs when software does not perform any authentication for functionality that requires a provable user identity. In SAP NetWeaver AS JAVA, the LM Configuration Wizard exposes critical configuration and user management capabilities without requiring any form of authentication, allowing unauthenticated remote attackers to create administrative accounts and execute configuration tasks with full system privileges.
Learn more: CWE-306 — Missing Authentication for Critical Function
Impact Analysis
CVE-2020-6287 carries the maximum CVSS 3.1 score of 10.0 (CRITICAL), indicating the most severe possible threat level. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication and no user interaction, making it trivially exploitable by any attacker with network access. The scope is changed, meaning exploitation can impact resources well beyond the vulnerable SAP NetWeaver component. Successful exploitation results in complete compromise of confidentiality, integrity, and availability, as attackers can create administrative users and execute arbitrary configuration tasks. The EPSS score of 94.36% (99.96th percentile) places this among the most likely vulnerabilities to be exploited across all tracked CVEs. Organizations running affected SAP NetWeaver AS JAVA versions (7.30, 7.31, 7.40, 7.50) face the highest level of risk and must treat remediation as an emergency priority.
Exploit Maturity
CVE-2020-6287 has highly mature exploitation capabilities. Public exploit code is available via Packet Storm Security, which provides a working proof-of-concept for the configuration task execution vulnerability. CISA has confirmed active exploitation in the wild by including this vulnerability in the Known Exploited Vulnerabilities catalog. The EPSS score of 94.36% (99.96th percentile) indicates near-certain exploitation activity, placing this among the top 0.04% of all tracked vulnerabilities for exploitation probability. The vulnerability was publicly disclosed by Onapsis as the "RECON" vulnerability, and its straightforward exploitation path through the unauthenticated LM Configuration Wizard makes it accessible to a wide range of threat actors.
Remediation
- Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. SAP Security Note 2934135 addresses this critical missing authentication vulnerability.
- Upgrade all affected SAP NetWeaver Application Server Java instances (versions 7.30, 7.31, 7.40, and 7.50) to the latest patched versions that enforce authentication on the LM Configuration Wizard.
- If immediate patching is not possible, disable the LM Configuration Wizard entirely and restrict network access to the SAP NetWeaver AS JAVA management interfaces using firewall rules and network segmentation to prevent unauthenticated access.
- Audit all SAP user accounts for unauthorized administrative accounts that may have been created through exploitation of this vulnerability, and review system configuration for unauthorized changes.
- Implement continuous monitoring for unauthenticated access attempts to the LM Configuration Wizard endpoint, and enforce authentication requirements on all critical administrative functions across the SAP landscape.
Technical Details
CVE-2020-6287 is a missing authentication vulnerability in the LM Configuration Wizard of SAP NetWeaver AS JAVA, affecting versions 7.30, 7.31, 7.40, and 7.50. The Configuration Wizard, which is designed for initial system setup and configuration, fails to enforce any authentication check, exposing critical system administration functions to unauthenticated users. The attack vector is network-based with low complexity (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), requiring no credentials and no user interaction. An attacker can leverage this flaw to execute configuration tasks that include creating new administrative user accounts with full SAP_ALL privileges, effectively gaining complete control over the SAP Java system. The changed scope and maximum impact across all CIA triad dimensions reflect that this vulnerability provides a direct path to full system compromise with potential lateral movement to connected SAP systems.
Frequently Asked Questions
Is CVE-2020-6287 being actively exploited?
Yes. CVE-2020-6287, known as the "RECON" vulnerability, is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 94.36% (99.96th percentile) indicates near-certain exploitation activity, making this one of the most actively targeted SAP vulnerabilities.
What products are affected by CVE-2020-6287?
CVE-2020-6287 affects SAP NetWeaver Application Server Java in versions 7.30, 7.31, 7.40, and 7.50. The vulnerability is in the LM Configuration Wizard component, and any SAP NetWeaver Java system with this component accessible is at risk.
How do I fix CVE-2020-6287?
Apply updates per SAP vendor instructions, specifically SAP Security Note 2934135. Upgrade all affected SAP NetWeaver AS JAVA instances to patched versions. If immediate patching is not possible, disable the LM Configuration Wizard and restrict all network access to SAP management interfaces.
How severe is CVE-2020-6287?
CVE-2020-6287 has the maximum CVSS 3.1 score of 10.0 (CRITICAL). It allows unauthenticated remote attackers to create administrative accounts and execute configuration tasks without any credentials. The EPSS score of 94.36% (99.96th percentile) makes this one of the most critical and actively exploited vulnerabilities in the SAP ecosystem.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.