CVE-2020-6249

HIGH

SAP Master Data Governance < S4CORE 101 - SQL Injection

Title source: llm
STIX 2.1

Description

The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2908560

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 60.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (5)
sap/master_data_governance_\(s4core\) 101
sap/master_data_governance_\(s4fnd\) 102
sap/master_data_governance_\(s4fnd\) 103
sap/master_data_governance_\(s4fnd\) 104
sap/master_data_governance_\(sap_bs_fnd\) 748
Published May 12, 2020
Tracked Since Feb 18, 2026