---
cve: "CVE-2020-6190"
severity: "MEDIUM"
cvss: 5.8
epss: "90%"
vendor: "SAP SE"
kev: false
exploited: false
published: "2020-02-12 20:15:14"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T13:02:12+02:00"
---

# CVE-2020-6190

> 5.8 MEDIUM

## Beschreibung

Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812>
- <https://launchpad.support.sap.com/#/notes/2838835>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-6190) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
