9.9
CVE-2020-6262
- EPSS 0.79%
- Veröffentlicht 12.05.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:24
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Application Server Version740
SAP ≫ Application Server Version2008_1_46c
SAP ≫ Application Server Version2008_1_620
SAP ≫ Application Server Version2008_1_640
SAP ≫ Application Server Version2008_1_700
SAP ≫ Application Server Version2008_1_710
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.79% | 0.716 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
cna@sap.com | 9.9 | 3.1 | 6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.