CVE-2020-26808Code Injection in SE SAP AS Abap

CWE-94Code Injection3 documents3 sources
Severity
7.2HIGHNVD
EPSS
3.7%
top 11.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 24

Description

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages4 packages

CVEListV5sap_se/sap_as_abap< 2011_1_620+7
CVEListV5sap_se/sap_s4_hana< 101+4
NVDsap/sap_as_abap8 versions+7
NVDsap/sap_s4_hana5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-49f8-w2xp-h8gq: SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions2022-05-24
CVEList
CVE-2020-26808: SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions2020-11-10
CVE-2020-26808 — Code Injection in SAP SE SAP AS Abap | cvebase