CVE-2020-6252

HIGH

SAP Adaptive Server Enterprise (Cockpit) <16.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact system availability.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2917090

Scores

CVSS v3 8.0
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
sap/adaptive_server_enterprise_cockpit 16.0
Published May 12, 2020
Tracked Since Feb 18, 2026