SQL Injection Vulnerability in SAP Master Data Governance
CVE-2020-6249

7.7HIGH

Summary

The vulnerability within SAP Master Data Governance arises from the improper handling of crafted database queries via the admin backend report. This imperfection allows attackers to execute unauthorized queries, potentially exposing sensitive data and back-end database structures. The affected versions suffer from flawed input validation, which can be exploited to manipulate the database, resulting in significant security risks. Organizations using these versions should prioritize remediation to mitigate potential attacks.

Affected Version(s)

SAP Master Data Governance (S4CORE) < 101

SAP Master Data Governance (S4FND) < 102 < 102

SAP Master Data Governance (S4FND) < 103 < 103

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.