
Cloud Vulnerability DB
A community-led vulnerabilities database
SAP Adaptive Server Enterprise (ASE) version 16.0 contains a critical vulnerability (CVE-2020-6250) that was disclosed in May 2020. The vulnerability allows an authenticated attacker to exploit misconfigured endpoints exposed over the adjacent network to read system administrator passwords, leading to information disclosure (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 6.8 (Medium) with the vector string CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. The attack requires adjacent network access and high privileges but no user interaction. The vulnerability affects confidentiality, integrity, and availability of the system (NVD).
If successfully exploited, this vulnerability could allow an attacker to read system administrator passwords, potentially leading to complete control over the database server. The attacker could gain the ability to read/write any data and even stop the server with administrator privileges (Hacker News).
The vulnerability requires an authenticated user with access to the adjacent network to exploit misconfigured endpoints. The attack complexity is considered low, but high privileges are required for successful exploitation (NVD).
SAP has addressed this vulnerability by releasing security patches in May 2020. Organizations using SAP ASE version 16.0 should apply the latest security updates to resolve this vulnerability (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."