← Back

CVE-2020-6244

nvd nist
Published: May 12, 2020Modified: May 27, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the application.

Affected (51)

Products: Sap: Business Client
1 product
Business Client
Configuration A
51 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 6.0
Version 6.0 patch_level10
Version 6.0 patch_level11
Version 6.0 patch_level12
Version 6.0 patch_level13
Version 6.0 patch_level14
Version 6.0 patch_level15
Version 6.0 patch_level16
Version 6.0 patch_level17
Version 6.0 patch_level1
Version 6.0 patch_level2
Version 6.0 patch_level3
Version 6.0 patch_level4
Version 6.0 patch_level5
Version 6.0 patch_level6
Version 6.0 patch_level7
Version 6.0 patch_level8
Version 6.0 patch_level9
Version 6.5
Version 6.5 patch_level10
Version 6.5 patch_level11
Version 6.5 patch_level12
Version 6.5 patch_level13
Version 6.5 patch_level14
Version 6.5 patch_level15
Version 6.5 patch_level16
Version 6.5 patch_level17
Version 6.5 patch_level18
Version 6.5 patch_level19
Version 6.5 patch_level1
Version 6.5 patch_level20
Version 6.5 patch_level21
Version 6.5 patch_level22
Version 6.5 patch_level2
Version 6.5 patch_level3
Version 6.5 patch_level4
Version 6.5 patch_level5
Version 6.5 patch_level6
Version 6.5 patch_level7
Version 6.5 patch_level8
Version 6.5 patch_level9
Version 7.0
Version 7.0 patch_level1
Version 7.0 patch_level2
Version 7.0 patch_level3
Version 7.0 patch_level4
Version 7.0 patch_level5
Version 7.0 patch_level6
Version 7.0 patch_level7
Version 7.0 patch_level8
Version 7.0 patch_level9

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.