CVE-2020-6318

HIGH

SAP NetWeaver <7.40 & ABAP Platform >7.40 - RCE

Title source: llm
STIX 2.1

Description

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.

References (4)

Core 4
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2958563
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/May/42

Scores

CVSS v3 7.2
EPSS 0.0613
EPSS Percentile 90.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (13)
sap/abap_platform 700
sap/abap_platform 701
sap/abap_platform 702
sap/abap_platform 710
sap/abap_platform 711
sap/abap_platform 730
sap/abap_platform 731
sap/abap_platform 740
sap/abap_platform 750
sap/abap_platform 751
... and 3 more
Published Sep 09, 2020
Tracked Since Feb 18, 2026