SQL Injection Vulnerability in SAP Adaptive Server Enterprise Web Services
CVE-2020-6253

7.2HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 May 2020

Summary

An SQL injection vulnerability exists in SAP Adaptive Server Enterprise (Web Services) versions 15.7 and 16.0. This issue enables authenticated users to execute specially crafted database queries, potentially allowing for unauthorized elevation of privileges, modification of database objects, and execution of commands that the user is not permitted to run. Addressing this vulnerability is crucial to maintaining the security and integrity of your database systems.

Affected Version(s)

SAP Adaptive Server Enterprise (Web Services) < 15.7 < 15.7

SAP Adaptive Server Enterprise (Web Services) < 16.0 < 16.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.