CVE-2020-26838: Code Injection
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-26838?
CVE-2020-26838 is a vulnerability in SAP Business Warehouse and SAP BW4HANA that allows an attacker with high developer privileges to execute code without user interaction.
Which software versions are affected by CVE-2020-26838?
CVE-2020-26838 affects SAP Business Warehouse versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA versions 100, 200.
What is the severity of CVE-2020-26838?
CVE-2020-26838 has a severity rating of 9.1 (critical).
How can an attacker exploit CVE-2020-26838?
An attacker with high developer privileges can exploit CVE-2020-26838 by submitting a crafted request to generate and execute code without requiring any user interaction.
How can I fix CVE-2020-26838?
To fix CVE-2020-26838, apply the necessary security patches provided by SAP and follow their recommended mitigation steps.