8.8

CVE-2020-6262

Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Application Server Version 740
SAP ≫ Application Server Version 2008_1_46c
SAP ≫ Application Server Version 2008_1_620
SAP ≫ Application Server Version 2008_1_640
SAP ≫ Application Server Version 2008_1_700
SAP ≫ Application Server Version 2008_1_710
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.17% 0.634
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
SAP 9.9 3.1 6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222
Vendor Advisory
https://launchpad.support.sap.com/#/notes/2835979
Permissions Required