8.8
CVSSv3

CVE-2020-6262

Published: 12/05/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Service Data Download in SAP Application Server ABAP (ST-PI, prior to 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an malicious user to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap application server 740

sap application server 2008_1_46c

sap application server 2008_1_620

sap application server 2008_1_640

sap application server 2008_1_700

sap application server 2008_1_710

Recent Articles

If you haven't yet patched this critical hole in SAP NetWeaver Application Server, today is not your day
The Register • Shaun Nichols in San Francisco • 12 Aug 2020

Full details of security vuln plus proof-of-concept exploits revealed We spent way too long on this Microsoft, Intel, Adobe, SAP, Red Hat Patch Tuesday article. Just click on it, pretend to read it, apply updates

We hope you've patched CVE-2020-6262, aka note 2835979, that affects SAP NetWeaver Application Server ABAP, because the folks who found and reported the vulnerability are going public with the details. SEC Consult will today, we're told, reveal the nitty-gritty of the flaw on its website, giving miscreants the info they need to exploit any vulnerable systems they can find. The infosec biz's Alexander Meier and Fabian Hag found the security hole and reported it to SAP in April. It was patched in ...

Sadly, 111 in this story isn't binary. It's decimal. It's the number of security fixes emitted by Microsoft this week
The Register • Shaun Nichols in San Francisco • 13 May 2020

Nothing too scary. Plus updates from SAP, Adobe, VMware One malicious MMS is all it takes to pwn a Samsung smartphone: Bug squashed amid Android patch batch

Patch Tuesday The May edition of Patch Tuesday landed this week. And there are scores of security fixes to install. A total of 111 fixes were released by Microsoft, though on the bright side none are being actively exploited, as far as we know. Sixteen earned Microsoft's top rating of critical, and range from remote code execution to elevation of privilege. One standout programming blunder was CVE-2020-1067, a remote-code execution (RCE) vulnerability in all supported versions of Windows. Anyone...