First published: Tue May 12 2020(Updated: )
The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Master Data Governance \(s4core\) | =101 | |
Sap Master Data Governance \(s4fnd\) | =102 | |
Sap Master Data Governance \(s4fnd\) | =103 | |
Sap Master Data Governance \(s4fnd\) | =104 | |
Sap Master Data Governance \(sap Bs Fnd\) | =748 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6249 has a critical severity rating due to the potential for SQL injection attacks.
To fix CVE-2020-6249, apply the latest patches released by SAP for the affected versions of Master Data Governance.
CVE-2020-6249 affects SAP Master Data Governance versions 101, 102, 103, 104, and 748.
CVE-2020-6249 is an SQL Injection vulnerability that allows attackers to execute arbitrary database queries.
CVE-2020-6249 can be exploited by attackers with access to the admin backend report of SAP Master Data Governance.