ZeroHour

CVE-2020-6248

CVSS 3.1
7.2 high
EPSS
2%p78
Published
()
Modified
Description

SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.

Vendors
sap
Products
adaptive server enterprise backup server
Weakness
CWE-20, CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news