CVE-2020-6318

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:abap_platform:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:755:*:*:*:*:*:*:*

History

21 Nov 2024, 05:35

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/167229/SAP-Application-Server-ABAP-ABAP-Platform-Code-Injection-SQL-Injection-Missing-Authorization.html - Exploit, Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2022/May/42 - Exploit, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2022/May/42 - Exploit, Mailing List, Third Party Advisory
References () https://launchpad.support.sap.com/#/notes/2958563 - Permissions Required () https://launchpad.support.sap.com/#/notes/2958563 - Permissions Required
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700 - Vendor Advisory

Information

Published : 2020-09-09 13:15

Updated : 2024-11-21 05:35


NVD link : CVE-2020-6318

Mitre link : CVE-2020-6318

CVE.ORG link : CVE-2020-6318


JSON object : View

Products Affected

sap

  • abap_platform
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')