← Back

CVE-2020-6318

nvd nist
Published: Sep 9, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.

Affected (13)

Products: Sap: Abap Platform
1 product
Abap Platform
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 700
Version 701
Version 702
Version 710
Version 711
Version 730
Version 731
Version 740
Version 750
Version 751
Version 753
Version 754
Version 755

References (8)

Source: cna@sap.com
ExploitMailing ListThird Party Advisory
Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.