Vulnerability Description
SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Client | 6.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2911801Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2911801Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
FAQ
What is CVE-2020-6244?
CVE-2020-6244 is a vulnerability with a CVSS score of 7.8 (HIGH). SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the applicatio...
How severe is CVE-2020-6244?
CVE-2020-6244 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6244?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business Client.