CVE-2020-6262 PUBLISHED CVSS 9.899999618530273 CRITICAL

Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.

EPSS 0.79% · 73.7th percentile

Risk Scores

CVSS v3.0
9.899999618530273
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.79%
73.7th percentile

Affected Products

VendorProductVersions
sapapplication_server2008_1_710, 740, 2008_1_46c
SAP SESAP Application Server ABAP (ST-PI)< 2008_1_46C, < 2008_1_620, < 2008_1_640

Timeline

References

Open in Interactive Console →