Back to overview

CVE-2020-6262

CRITICAL
9.9
CVSS 3.0
Description
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.

Metadata

CVE ID
CVE-2020-6262
State
PUBLISHED
Assigner
sap
Reserved
2020-01-08 00:00 UTC
Published
2020-05-12 17:51 UTC
Last updated
2024-08-04 08:55 UTC
Vendor / Product
SAP SE / SAP Application Server ABAP (ST-PI)
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
SAP SE SAP Application Server ABAP (ST-PI) < 2008_1_46C, < 2008_1_620, < 2008_1_640, < 2008_1_700 …
Weakness (CWE)
CWESourceDescription
cna Code Injection
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview