CVE-2020-6236

Severity
7.2HIGH
EPSS
0.2%
top 56.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateMay 24

Description

SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-qrvg-vrjq-42gc: SAP Landscape Management, version 32022-05-24
CVEList
CVE-2020-6236: SAP Landscape Management, version 32020-04-14
CVE-2020-6236 (HIGH CVSS 7.2) | SAP Landscape Management | cvebase.io