CVE-2020-6249 HIGH

CVE-2020-6249

Vendor Sap Se
Product SAP Master Data Governance (S4CORE)
Published May 12, 2020
Last update August 4, 2024

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.

Key dates

02Disclosure timeline

May 12, 2020 CVE published
August 4, 2024 Record updated