First published: Tue May 12 2020(Updated: )
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Web Application Server | =740 | |
SAP Web Application Server | =2008_1_46c | |
SAP Web Application Server | =2008_1_620 | |
SAP Web Application Server | =2008_1_640 | |
SAP Web Application Server | =2008_1_700 | |
SAP Web Application Server | =2008_1_710 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6262 is considered a critical vulnerability that allows code injection in the SAP Application Server ABAP.
To fix CVE-2020-6262, you should update your SAP Application Server ABAP to one of the patched versions listed in the SAP advisory.
CVE-2020-6262 affects SAP Application Server ABAP versions prior to 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, and 740.
The potential impacts of CVE-2020-6262 include unauthorized code execution and control over the SAP application by an attacker.
While the primary recommendation is to apply the update, temporary mitigation methods may involve restricting access to vulnerable functionalities.