PT-2020-5977 · Sap · Abap Platform+2

Published

2020-08-11

·

Updated

2022-10-05

·

CVE-2020-6296

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver (ABAP Server) and ABAP Platform, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755
Description The issue allows an attacker to inject code that can be executed by the application, leading to code injection. This can enable an attacker to control the behavior of the application. The vulnerability is related to incorrect code generation management in the ABAP Server component of the SAP NetWeaver platform. Exploitation of the vulnerability may allow a remote attacker to inject arbitrary code.
Recommendations For versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-02169
CVE-2020-6296

Affected Products

Abap Platform
Abap Server
Sap Netweaver