CVE-2020-6296: Code Injection
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6296?
CVE-2020-6296 is a vulnerability in SAP NetWeaver (ABAP Server) and ABAP Platform versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755.
What is the severity of CVE-2020-6296?
The severity of CVE-2020-6296 is high with a CVSS score of 8.8.
What is the impact of CVE-2020-6296?
CVE-2020-6296 allows an attacker to inject code that can be executed by the application, leading to Code Injection and potential control of the application's behavior.
Which software versions are affected by CVE-2020-6296?
SAP NetWeaver (ABAP Server) and ABAP Platform versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755 are affected by CVE-2020-6296.
How can I fix CVE-2020-6296?
To fix CVE-2020-6296, SAP has provided patches and recommends applying the necessary security updates. Please refer to SAP's security notes and documentation for detailed instructions.