PT-2020-19028 · Sap · Sap Orientdb

Published

2020-04-14

·

Updated

2021-07-21

·

CVE-2020-6230

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP OrientDB version 3.0
Description The issue allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application, leading to code injection. This enables the attacker to control the behavior of the application.
Recommendations For SAP OrientDB version 3.0, consider restricting script execute/write permissions to prevent code injection until a patch is available. As a temporary workaround, review and monitor application behavior closely for signs of unauthorized code execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-6230

Affected Products

Sap Orientdb