CVE-2020-6253 PUBLISHED CVSS 7.199999809265137 HIGH

Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or execute commands they are not otherwise authorized to execute, leading to SQL Injection.

EPSS 0.57% · 68.6th percentile

Risk Scores

CVSS v3.0
7.199999809265137
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.57%
68.6th percentile

Affected Products

VendorProductVersions
sapadaptive_server_enterprise15.7, 16.0
SAP SESAP Adaptive Server Enterprise (Web Services)< 15.7, < 16.0

Timeline

References

Open in Interactive Console →