CVE-2020-6287, also known as RECON, is a missing authentication vulnerability in the LM Configuration Wizard of SAP NetWeaver AS Java versions 7.30, 7.31, 7.40, and 7.50. The component fails to enforce authentication before executing configuration tasks. A remote unauthenticated attacker can perform critical actions against the SAP Java system, including creating an administrative user, enabling takeover of affected SAP applications and systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit auxiliary module targeting SAP NetWeaver systems vulnerable to CVE-2020-6287 (RECON). The module exploits an unauthenticated SOAP web service (CTCWebService) to create or remove users with arbitrary roles (defaulting to Administrator) on the target SAP system. The exploit works by submitting a job to the CTCWebService endpoint, monitoring its progress, and then canceling the job to minimize system changes. The module provides two actions: 'ADD' (create user) and 'REMOVE' (delete user). The main fingerprintable endpoint is the '/CTCWebService/CTCWebServiceBean' path, typically accessible on port 50000. The exploit is operational and can be used to gain administrative access to vulnerable SAP systems without authentication. The code is written in Ruby and is designed to be run within the Metasploit framework.
This repository contains a Python proof-of-concept exploit (RECON.py) for the SAP RECON vulnerabilities CVE-2020-6287 and CVE-2020-6286 affecting SAP NetWeaver Application Server Java (LM Configuration Wizard). The exploit leverages missing authentication and a directory traversal flaw in the 'queryProtocol' SOAP method exposed at the /CTCWebService/CTCWebServiceBean endpoint. The script provides several capabilities: (1) checking if a target is vulnerable, (2) downloading arbitrary ZIP files from the server via directory traversal, (3) creating a new SAP Java user with standard privileges, and (4) creating a new SAP Java user with Administrator privileges. The exploit is operational and requires the attacker to specify the target host, port, and desired action via command-line arguments. The main attack vector is network-based, targeting the SOAP web service endpoint over HTTP(S). The repository consists of a single Python exploit script, a README with usage instructions and background, and a .gitignore file.
This repository provides a Python proof-of-concept exploit for CVE-2020-6287, a critical unauthenticated remote code execution vulnerability in SAP NetWeaver. The exploit consists of a single Python script ('sap-CVE-2020-6287-add-user.py') and a README file. The script allows an attacker to create a new user with arbitrary credentials on a vulnerable SAP NetWeaver system by sending a specially crafted SOAP request to the '/CTCWebService/CTCWebServiceBean/ConfigServlet' endpoint. The exploit first checks if the target is vulnerable by accessing the WSDL at '/CTCWebService/CTCWebServiceBean?wsdl'. If the target is vulnerable, it sends a base64-encoded XML payload to create a new user. The exploit does not grant administrator privileges to the new user. The README provides usage instructions and references to the original Metasploit module and research. The attack vector is network-based, requiring only HTTP(S) access to the target system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.