cbcvebase.
CVE-2020-6250
published 2020-05-12

CVE-2020-6250: SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to…

PriorityP431medium6.8CVSS 3.1
AVAACLPRHUINSUCHIHAH
EPSS
0.52%
40.4th percentile
SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read system administrator password leading to Information Disclosure. This could help the attacker to read/write any data and even stop the server like an administrator.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapadaptive_server_enterprise
sap_sesap_adaptive_server_enterprise< 16.016.0

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.8MEDIUMCVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.7MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.