Privilege Escalation Vulnerability in SAP Landscape Management and Adaptive Extensions
CVE-2020-6236

7.2HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 April 2020

Summary

A vulnerability exists in SAP Landscape Management version 3.0 and SAP Adaptive Extensions version 1.0 that permits an attacker with admin_group privileges to alter the ownership and permissions of arbitrary files remotely. This manipulation can lead to unauthorized execution of files as the root user from a non-root context, posing significant security risks and potential exploitation.

Affected Version(s)

SAP Adaptive Extensions < 1.0

SAP Landscape Management < 3.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.