CVE-2020-6203
CVE-2020-6203 is a critical-severity vulnerability in Sap Netweaver with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- CVSS v2: 6.4
- EPSS exploit prediction: 2% (79th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-22
- Affected product: Sap Netweaver
- Published:
- Last modified:
Description
SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.
Frequently asked questions
- What is CVE-2020-6203?
- SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.
- How severe is CVE-2020-6203?
- CVE-2020-6203 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2020-6203 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (79th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-6203?
- CVE-2020-6203 primarily affects Sap Netweaver. In total, 7 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2020-6203?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2020-6203 published?
- CVE-2020-6203 was published on 2020-03-10 and last updated on 2026-06-17.
References
- https://launchpad.support.sap.com/#/notes/2806198
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305
Affected products (7)
- cpe:2.3:a:sap:netweaver:7.10:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.11:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.20:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver:7.50:*:*:*:*:*:*:*
More vulnerabilities in Sap Netweaver
- CVE-2025-31324 — Critical (CVSS 10.0): SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated…
- CVE-2013-6822 — Critical (CVSS 10.0): GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML…
- CVE-2021-38163 — Critical (CVSS 9.9): SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker…
- CVE-2011-1517 — Critical (CVSS 9.8): SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function.…
- CVE-2013-1592 — Critical (CVSS 9.8): A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending…
- CVE-2015-7241 — Critical (CVSS 9.8): XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
All CVEs affecting Sap Netweaver →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-55393 — Critical (CVSS 10.0): Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9…
- CVE-2026-97163 — Critical (CVSS 10.0): Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
- CVE-2026-80155 — Critical (CVSS 10.0): Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1,…
- CVE-2026-70200 — Critical (CVSS 10.0): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an…
- CVE-2026-85706 — Critical (CVSS 10.0): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9,…
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.