First published: Tue May 12 2020(Updated: )
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Adaptive Server Enterprise Backup Server | =16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6248 is classified as a high-severity vulnerability due to its ability to allow arbitrary code execution.
To mitigate CVE-2020-6248, it is recommended to apply the latest security patches provided by SAP for version 16.0 of the Adaptive Server Enterprise Backup Server.
CVE-2020-6248 specifically affects SAP Adaptive Server Enterprise Backup Server version 16.0.
CVE-2020-6248 enables attackers to execute arbitrary code or perform code injection via DUMP or LOAD commands without proper validation.
Yes, CVE-2020-6248 can potentially be exploited by authenticated users without proper validation checks, posing risks for remote attacks.