The RECON vulnerability affects SAP NetWeaver AS JAVA (LM Configuration Wizard) versions 7.30 to 7.50, a core component of several solutions and products deployed in most SAP environments. The vulnerability is rated with a maximum CVSS score of 10 out of 10 and can be exploited remotely by unauthenticated attackers to fully compromise unpatched SAP systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also issued an advisory today where the vulnerability is being tracked as CVE-2020-6287.
Source: https://www.bleepingcomputer.com/news/security/critical-sap-recon-flaw-exposes-thousands-of-customers-to-attacks/

