Code Injection Vulnerability in SAP Adaptive Server Enterprise by SAP
CVE-2020-6243
8HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 12 May 2020
Summary
SAP Adaptive Server Enterprise, specifically on the Windows Platform in versions 15.7 and 16.0, fails to adequately verify the authenticity of users during the execution of extended stored procedures. This oversight can be exploited by attackers to gain unauthorized access to restricted areas, enabling them to read, modify, or delete sensitive data across connected servers. This vulnerability raises serious concerns regarding database security and data integrity.
Affected Version(s)
SAP Adaptive Server Enterprise (XP Server on Windows Platform) < 15.7 < 15.7
SAP Adaptive Server Enterprise (XP Server on Windows Platform) < 16.0 < 16.0
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved