CVE-2020-6250

MEDIUM

SAP Adaptive Server Enterprise 16.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read system administrator password leading to Information Disclosure. This could help the attacker to read/write any data and even stop the server like an administrator.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2917022

Scores

CVSS v3 6.8
EPSS 0.0008
EPSS Percentile 23.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
sap/adaptive_server_enterprise 16.0
Published May 12, 2020
Tracked Since Feb 18, 2026