The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2908560 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-05-12 18:15
Updated : 2024-02-28 17:47
NVD link : CVE-2020-6249
Mitre link : CVE-2020-6249
CVE.ORG link : CVE-2020-6249
JSON object : View
Products Affected
sap
- master_data_governance_\(s4core\)
- master_data_governance_\(sap_bs_fnd\)
- master_data_governance_\(s4fnd\)
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')