Code Injection Vulnerability in SAP Adaptive Server Enterprise by SAP
CVE-2020-6243

8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 May 2020

Summary

SAP Adaptive Server Enterprise, specifically on the Windows Platform in versions 15.7 and 16.0, fails to adequately verify the authenticity of users during the execution of extended stored procedures. This oversight can be exploited by attackers to gain unauthorized access to restricted areas, enabling them to read, modify, or delete sensitive data across connected servers. This vulnerability raises serious concerns regarding database security and data integrity.

Affected Version(s)

SAP Adaptive Server Enterprise (XP Server on Windows Platform) < 15.7 < 15.7

SAP Adaptive Server Enterprise (XP Server on Windows Platform) < 16.0 < 16.0

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.