7.2

CVE-2020-6318

Exploit
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Abap Platform Version 700
SAP ≫ Abap Platform Version 701
SAP ≫ Abap Platform Version 702
SAP ≫ Abap Platform Version 710
SAP ≫ Abap Platform Version 711
SAP ≫ Abap Platform Version 730
SAP ≫ Abap Platform Version 731
SAP ≫ Abap Platform Version 740
SAP ≫ Abap Platform Version 750
SAP ≫ Abap Platform Version 751
SAP ≫ Abap Platform Version 753
SAP ≫ Abap Platform Version 754
SAP ≫ Abap Platform Version 755
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.64% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
SAP 9.1 2.3 6
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
Vendor Advisory
http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html
Third Party Advisory
Exploit
VDB Entry
http://seclists.org/fulldisclosure/2022/May/42
Third Party Advisory
Exploit
Mailing List
https://launchpad.support.sap.com/#/notes/2958563
Permissions Required