CVE-2020-6253: SQL Injection
Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or execute commands they are not otherwise authorized to execute, leading to SQL Injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6253?
CVE-2020-6253 has a critical severity rating as it allows authenticated users to execute unauthorized SQL commands.
How do I fix CVE-2020-6253?
To fix CVE-2020-6253, apply the latest security patches provided by SAP for versions 15.7 and 16.0 of Adaptive Server Enterprise.
What versions of SAP Adaptive Server Enterprise are affected by CVE-2020-6253?
CVE-2020-6253 affects SAP Adaptive Server Enterprise versions 15.7 and 16.0.
Can an unauthenticated user exploit CVE-2020-6253?
No, CVE-2020-6253 requires authentication, as it is an issue related to an authenticated user’s privileges.
What kind of attacks can CVE-2020-6253 enable?
CVE-2020-6253 can enable attackers to elevate their privileges, modify database objects, or execute unauthorized commands.