cbcvebase.
CVE-2020-6243
published 2020-05-12

CVE-2020-6243: Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure, allowing an attacker to read, modify, delete restricted data on connected servers, leading to Code Injection.

Affected

4 ranges
VendorProductVersion rangeFixed in
sapadaptive_server_enterprise
sapadaptive_server_enterprise
sap_sesap_adaptive_server_enterprise< 15.715.7
sap_sesap_adaptive_server_enterprise< 16.016.0