CVE-2020-6295

HIGH

SAP Adaptive Server Enterprise 16.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compromise of the installed Cockpit. This compromise could enable the attacker to view, modify and/or make unavailable any data associated with the Cockpit, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2941332

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-532 CWE-732
Status published
Products (1)
sap/adaptive_server_enterprise 16.0
Published Aug 12, 2020
Tracked Since Feb 18, 2026