Lucene search

K
cveSapCVE-2020-26808
HistoryNov 10, 2020 - 5:15 p.m.

CVE-2020-26808

2020-11-1017:15:13
sap
web.nvd.nist.gov
28
2
cve-2020-26808
sap
as abap
dmis
s4 hana
code injection
confidentiality
availability
integrity

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.075

Percentile

94.2%

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application.

Affected configurations

Nvd
Node
sapsap_as_abap\(dmis\)Match2011_1_620
OR
sapsap_as_abap\(dmis\)Match2011_1_640
OR
sapsap_as_abap\(dmis\)Match2011_1_700
OR
sapsap_as_abap\(dmis\)Match2011_1_710
OR
sapsap_as_abap\(dmis\)Match2011_1_730
OR
sapsap_as_abap\(dmis\)Match2011_1_731
OR
sapsap_as_abap\(dmis\)Match2011_1_752
OR
sapsap_as_abap\(dmis\)Match2020
OR
sapsap_s4_hana\(dmis\)Match101
OR
sapsap_s4_hana\(dmis\)Match102
OR
sapsap_s4_hana\(dmis\)Match103
OR
sapsap_s4_hana\(dmis\)Match104
OR
sapsap_s4_hana\(dmis\)Match105
VendorProductVersionCPE
sapsap_as_abap\(dmis\)2011_1_620cpe:2.3:a:sap:sap_as_abap\(dmis\):2011_1_620:*:*:*:*:*:*:*
sapsap_as_abap\(dmis\)2011_1_640cpe:2.3:a:sap:sap_as_abap\(dmis\):2011_1_640:*:*:*:*:*:*:*
sapsap_as_abap\(dmis\)2011_1_700cpe:2.3:a:sap:sap_as_abap\(dmis\):2011_1_700:*:*:*:*:*:*:*
sapsap_as_abap\(dmis\)2011_1_710cpe:2.3:a:sap:sap_as_abap\(dmis\):2011_1_710:*:*:*:*:*:*:*
sapsap_as_abap\(dmis\)2011_1_730cpe:2.3:a:sap:sap_as_abap\(dmis\):2011_1_730:*:*:*:*:*:*:*
sapsap_as_abap\(dmis\)2011_1_731cpe:2.3:a:sap:sap_as_abap\(dmis\):2011_1_731:*:*:*:*:*:*:*
sapsap_as_abap\(dmis\)2011_1_752cpe:2.3:a:sap:sap_as_abap\(dmis\):2011_1_752:*:*:*:*:*:*:*
sapsap_as_abap\(dmis\)2020cpe:2.3:a:sap:sap_as_abap\(dmis\):2020:*:*:*:*:*:*:*
sapsap_s4_hana\(dmis\)101cpe:2.3:a:sap:sap_s4_hana\(dmis\):101:*:*:*:*:*:*:*
sapsap_s4_hana\(dmis\)102cpe:2.3:a:sap:sap_s4_hana\(dmis\):102:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CNA Affected

[
  {
    "product": "SAP AS ABAP(DMIS)",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 2011_1_620"
      },
      {
        "status": "affected",
        "version": "< 2011_1_640"
      },
      {
        "status": "affected",
        "version": "< 2011_1_700"
      },
      {
        "status": "affected",
        "version": "< 2011_1_710"
      },
      {
        "status": "affected",
        "version": "< 2011_1_730"
      },
      {
        "status": "affected",
        "version": "< 2011_1_731"
      },
      {
        "status": "affected",
        "version": "< 2011_1_752"
      },
      {
        "status": "affected",
        "version": "< 2020"
      }
    ]
  },
  {
    "product": "SAP S4 HANA(DMIS)",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 101"
      },
      {
        "status": "affected",
        "version": "< 102"
      },
      {
        "status": "affected",
        "version": "< 103"
      },
      {
        "status": "affected",
        "version": "< 104"
      },
      {
        "status": "affected",
        "version": "< 105"
      }
    ]
  }
]

Social References

More

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0.075

Percentile

94.2%

Related for CVE-2020-26808