CVE-2020-6318 Information
Feb 14, 2021
cve
Description
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server up to release 7.40) and ABAP Platform ( release 7.40).Because of this an attacker can exploit these products via Code Injection and potentially enabling to take complete control of the products including viewing changing or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product causing the products to terminate.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Reference
https://launchpad.support.sap.com//notes/2958563 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.2
Share on: