9.1

CVE-2020-26838

SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Business Warehouse Version 700
SAP ≫ Business Warehouse Version 701
SAP ≫ Business Warehouse Version 702
SAP ≫ Business Warehouse Version 731
SAP ≫ Business Warehouse Version 740
SAP ≫ Business Warehouse Version 750
SAP ≫ Business Warehouse Version 751
SAP ≫ Business Warehouse Version 752
SAP ≫ Business Warehouse Version 753
SAP ≫ Business Warehouse Version 754
SAP ≫ Business Warehouse Version 755
SAP ≫ Business Warehouse Version 782
SAP ≫ Bw/4hana Version 100
SAP ≫ Bw/4hana Version 200
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.15% 0.798
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 2.3 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
SAP 9.1 2.3 6
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564757079
Vendor Advisory
https://launchpad.support.sap.com/#/notes/2983367
Permissions Required