7.2
CVE-2020-6318
- EPSS 5.64%
- Veröffentlicht 09.09.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:29
- Erkennungen
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Abap Platform Version 700
SAP ≫ Abap Platform Version 701
SAP ≫ Abap Platform Version 702
SAP ≫ Abap Platform Version 710
SAP ≫ Abap Platform Version 711
SAP ≫ Abap Platform Version 730
SAP ≫ Abap Platform Version 731
SAP ≫ Abap Platform Version 740
SAP ≫ Abap Platform Version 750
SAP ≫ Abap Platform Version 751
SAP ≫ Abap Platform Version 753
SAP ≫ Abap Platform Version 754
SAP ≫ Abap Platform Version 755
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.64% | 0.92 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
| SAP | 9.1 | 2.3 | 6 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html
http://seclists.org/fulldisclosure/2022/May/42
https://launchpad.support.sap.com/#/notes/2958563