CVE Database
/

CVE-2020-26838

Back to search

CVE-2020-26838

Published: Dec 9, 2020

Modified: Aug 4, 2024

PUBLISHED

CVSS v3.0

9.1

CRITICAL

Description

SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.

VendorProductVersions

SAP SE

SAP Business Warehouse

affected
< 700
affected
< 701
affected
< 702
affected
< 731
affected
< 740

+7 more versions

SAP SE

SAP BW4HANA

affected
< 100
affected
< 200

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now