Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure, allowing an attacker to read, modify, delete restricted data on connected servers, leading to Code Injection.
References
| Link | Resource |
|---|---|
| https://launchpad.support.sap.com/#/notes/2915585 | Permissions Required |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-05-12 18:15
Updated : 2021-07-21 11:39
NVD link : CVE-2020-6243
Mitre link : CVE-2020-6243
JSON object : View
Products Affected
sap
- adaptive_server_enterprise
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
