logo

SAP Vulnerability as Severe as it Gets

ID: 58f465ea-af45-5bf4-9253-20f5cdccedf7

STIX ID: report--58f465ea-af45-5bf4-9253-20f5cdccedf7

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2020-07-15

Date Updated: 2026-04-27

...
...

CVE-2020-6287 (“RECON”) is a critical, unauthenticated remote code execution vulnerability in SAP NetWeaver AS Java (CVSS 10) that allows attackers to create highly privileged users, execute arbitrary code, and compromise confidentiality, integrity, and availability; Censys reports roughly 10,000 Internet-facing vulnerable instances (including dozens of Fortune 500 companies), urges immediate patching, and provides detection/query examples for affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.