cbcvebase.
CVE-2020-6244
published 2020-05-12

CVE-2020-6244: SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the application.

Affected

4 ranges
VendorProductVersion rangeFixed in
sapbusiness_client
sapbusiness_client
sapbusiness_client
sap_sesap_business_client< 7.07.0