CVE-2020-26832

HIGHCVSS 7.6/10EPSS 2.16%

Last modified

CVE-2020-26832 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.. EPSS estimates a 2.16% chance of exploitation in the next 30 days.

Description

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.

Metrics

CVSS 3.1
7.6/10

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H

EPSS Probability
2.16%

79.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SapNetweaver Application Server Abap2011_1_620
SapNetweaver Application Server Abap2011_1_640
SapNetweaver Application Server Abap2011_1_700
SapNetweaver Application Server Abap2011_1_710
SapNetweaver Application Server Abap2011_1_730
SapNetweaver Application Server Abap2011_1_731
SapNetweaver Application Server Abap2011_1_752
SapNetweaver Application Server Abap2020
SapS\/4 Hana101
SapS\/4 Hana102
SapS\/4 Hana103
SapS\/4 Hana104
SapS\/4 Hana105

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-26832?
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to which access should be restricted, however due to missing authorization an attacker can get access to some sensitive internal information of vulnerable SAP system or to make vulnerable SAP systems completely unavailable.
How severe is CVE-2020-26832?
CVE-2020-26832 has a CVSS score of 7.6/10 (HIGH severity). The EPSS model estimates a 2.16% probability of exploitation in the next 30 days.
How do I fix CVE-2020-26832?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-26832?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST