← Retour aux CVEs
CVE-2020-6318
HIGH7.2
Description
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.
Details CVE
Score CVSS v3.17.2
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie9/9/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
sap:abap_platform
Faiblesses (CWE)
CWE-94
References
http://seclists.org/fulldisclosure/2022/May/42(cna@sap.com)
https://launchpad.support.sap.com/#/notes/2958563(cna@sap.com)
http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2022/May/42(af854a3a-2127-422b-91ae-364da2661108)
https://launchpad.support.sap.com/#/notes/2958563(af854a3a-2127-422b-91ae-364da2661108)
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.