CVE-2020-6262
SAP Application Server vulnerability analysis and mitigation

Overview

Service Data Download in SAP Application Server ABAP (ST-PI) contains a code injection vulnerability affecting versions before 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, and 740. The vulnerability was discovered and disclosed in January 2020 (NVD, CVE).

Technical details

The vulnerability allows an attacker to inject code that can be executed by the application. It has been assigned CVE-2020-6262 with a CVSS v3.1 base score of 8.8 (HIGH) by NVD and 9.9 (CRITICAL) by SAP SE. The vulnerability is classified as CWE-94: Improper Control of Generation of Code (Code Injection) (NVD).

Impact

If successfully exploited, an attacker could control the behavior of the application and the whole ABAP system through code injection, potentially leading to complete system compromise (CVE).

Exploitability

The vulnerability requires low attack complexity and can be exploited remotely with low privileges and no user interaction (NVD).

Mitigation and workarounds

SAP has released security patches for the affected versions. Users should upgrade to versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, or 740 or later to address this vulnerability (SAP Note).

Additional resources


SourceThis report was generated using AI

Related SAP Application Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-6262HIGH8.8
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:application_server
NoNoMay 12, 2020
CVE-2007-3615HIGH7.8
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:sap_web_application_server
NoNoJul 06, 2007
CVE-2009-4603MEDIUM5
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:sap_kernel
NoYesJan 12, 2010
CVE-2015-7968MEDIUM4.3
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:netweaver_application_server
NoYesMar 09, 2020
CVE-2008-2421MEDIUM4.3
  • SAP Application Server logoSAP Application Server
  • cpe:2.3:a:sap:sap_web_application_server
NoNoMay 23, 2008

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management