7.5
CVSSv3

CVE-2020-6304

Published: 14/01/2020 Updated: 24/01/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49 KERNEL 7.21, 7.49, 7.53) allows an malicious user to prevent users from accessing its services through a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver internet communication manager \\(kernel\\) 7.21

sap netweaver internet communication manager \\(kernel\\) 7.22

sap netweaver internet communication manager \\(kernel\\) 7.49

sap netweaver internet communication manager \\(kernel\\) 7.53

sap netweaver internet communication manager \\(krnl32nuc\\) 7.21

sap netweaver internet communication manager \\(krnl32nuc\\) 7.21ext

sap netweaver internet communication manager \\(krnl32nuc\\) 7.22

sap netweaver internet communication manager \\(krnl32nuc\\) 7.22ext

sap netweaver internet communication manager \\(krnl32uc\\) 7.21

sap netweaver internet communication manager \\(krnl32uc\\) 7.21ext

sap netweaver internet communication manager \\(krnl32uc\\) 7.22

sap netweaver internet communication manager \\(krnl32uc\\) 7.22ext

sap netweaver internet communication manager \\(krnl64nuc\\) 7.21

sap netweaver internet communication manager \\(krnl64nuc\\) 7.21ext

sap netweaver internet communication manager \\(krnl64nuc\\) 7.22

sap netweaver internet communication manager \\(krnl64nuc\\) 7.22ext

sap netweaver internet communication manager \\(krnl64nuc\\) 7.49

sap netweaver internet communication manager \\(krnl64uc\\) 7.21

sap netweaver internet communication manager \\(krnl64uc\\) 7.21ext

sap netweaver internet communication manager \\(krnl64uc\\) 7.22

sap netweaver internet communication manager \\(krnl64uc\\) 7.22ext

sap netweaver internet communication manager \\(krnl64uc\\) 7.49

Recent Articles

Welcome to the 2020s: Booby-trapped Office files, NSA tipping off Windows cert-spoofing bugs, RDP flaws...
The Register • Shaun Nichols in San Francisco • 14 Jan 2020

Grab your Microsoft, Adobe, SAP, Intel, and VMware fixes now The four problems with the US government's latest rulebook on security bug disclosures

Patch Tuesday In the first Patch Tuesday of the year, Microsoft finds itself joined by Adobe, Intel, VMware, and SAP in dropping scheduled security updates. This month's Microsoft security fixes include three more remote-code-execution vulnerabilities in Redmond's Windows Remote Desktop Protocol software. Two of the flaws (CVE-2020-0609, CVE-2020-0610) are present on the server side in RD Gateway – requiring no authentication – while a third (CVE-2020-0611) is found on the client side. Dusti...