CVE-2020-26832 PUBLISHED CVSS 7.599999904632568 HIGH

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.

EPSS 0.49% · 65.6th percentile

Risk Scores

CVSS v3.0
7.599999904632568
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
EPSS Score
0.49%
65.6th percentile

Affected Products

VendorProductVersions
saps\/4_hana105, 104, 103
SAP SESAP NetWeaver AS ABAP (SAP Landscape Transformation)< 2011_1_731, < 2011_1_752, < 2020
sapnetweaver_application_server_abap2011_1_620, 2011_1_640, 2011_1_700
SAP SESAP S4 HANA (SAP Landscape Transformation)< 105, < 104, < 103

Timeline

References

Open in Interactive Console →