CVE-2020-6262
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
12/05/2020
Last modified:
21/07/2021
Description
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sap:application_server:740:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:application_server:2008_1_46c:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:application_server:2008_1_620:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:application_server:2008_1_640:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:application_server:2008_1_700:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:application_server:2008_1_710:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page