CVE-2020-6296

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:abap_platform:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:710:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:711:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_abap:755:*:*:*:*:*:*:*

Information

Published : 2020-08-12 14:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-6296

Mitre link : CVE-2020-6296


JSON object : View

Products Affected

sap

  • abap_platform
  • netweaver_as_abap
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')