Vulnerability Description
Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or execute commands they are not otherwise authorized to execute, leading to SQL Injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Adaptive Server Enterprise | 15.7 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2917273Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2917273Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
FAQ
What is CVE-2020-6253?
CVE-2020-6253 is a vulnerability with a CVSS score of 7.2 (HIGH). Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify datab...
How severe is CVE-2020-6253?
CVE-2020-6253 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6253?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Adaptive Server Enterprise.