← Back

CVE-2020-26832

nvd nist
Published: Dec 9, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
Exploitability: 2.3 / Impact: 4.7
Source: NVD

Description

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.

Affected (13)

2 products
Netweaver Application Server Abap
S/4 Hana
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 2011_1_620
Version 2011_1_640
Version 2011_1_700
Version 2011_1_710
Version 2011_1_730
Version 2011_1_731
Version 2011_1_752
Version 2020
Sap
Version 101
Version 102
Version 103
Version 104
Version 105

References (8)

Source: cna@sap.com
ExploitMailing ListThird Party Advisory
Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.