cbcvebase.
CVE-2020-6252
published 2020-05-12

CVE-2020-6252: Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and…

PriorityP339high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.52%
40.5th percentile
Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact system availability.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapadaptive_server_enterprise_cockpit
sap_sesap_adaptive_server_enterprise< 16.016.0

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.0CRITICALCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.05.2MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.