Vulnerability CVE-2020-26808


Published: 2020-11-10

Description:
SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
SAP Application Server ABAP / ABAP Platform Code Injection / SQL Injection / Missing Authorization
Fabian Hagg
22.05.2022

 References:
https://launchpad.support.sap.com/#/notes/2973735
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571

Copyright 2024, cxsecurity.com

 

Back to Top