PT-2020-19046 · Sap · Sap Adaptive Server Enterprise
Published
2020-05-12
·
Updated
2021-07-21
·
CVE-2020-6250
CVSS v3.1
6.8
Medium
| Vector | AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Adaptive Server Enterprise version 16.0
Description
The issue allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read the system administrator password, leading to information disclosure. This could enable the attacker to read or write any data and even stop the server with administrator privileges.
Recommendations
For SAP Adaptive Server Enterprise version 16.0, consider restricting access to the misconfigured endpoints exposed over the adjacent network as a temporary workaround until a patch is available. Additionally, review and secure the configuration of the endpoints to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Adaptive Server Enterprise