First published: Tue Apr 14 2020(Updated: )
SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application and lead to Code Injection. An attacker could thereby control the behavior of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP OrientDB | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6230 has a high severity rating due to the potential for code injection vulnerabilities in SAP OrientDB.
To fix CVE-2020-6230, update SAP OrientDB to a version that addresses the code injection vulnerability.
CVE-2020-6230 affects users of SAP OrientDB version 3.0 with script execute/write permissions.
The potential impacts of CVE-2020-6230 include unauthorized control over application behavior through code execution.
No, CVE-2020-6230 requires authenticated access, making it an authenticated code injection vulnerability.