| |
Vulnerability CVE-2020-6252
Published: 2020-05-12
Description: |
Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact system availability. |
Type:
CWE-200 (Information Exposure)
CVSS2 => (AV:A/AC:L/Au:S/C:P/I:P/A:P)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5.2/10 |
6.4/10 |
5.1/10 |
Exploit range |
Attack complexity |
Authentication |
Adjacent network |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
Partial |
References: |
https://launchpad.support.sap.com/#/notes/2917090
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|