CVE-2020-6262
CVE-2020-6262
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.9EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 May 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
SAP SE · SAP Application Server ABAP (ST-PI)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →