CVE-2020-26838
Last modified
CVE-2020-26838 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Warehouse | 700 |
| Sap | Business Warehouse | 701 |
| Sap | Business Warehouse | 702 |
| Sap | Business Warehouse | 731 |
| Sap | Business Warehouse | 740 |
| Sap | Business Warehouse | 750 |
| Sap | Business Warehouse | 751 |
| Sap | Business Warehouse | 752 |
| Sap | Business Warehouse | 753 |
| Sap | Business Warehouse | 754 |
| Sap | Business Warehouse | 755 |
| Sap | Business Warehouse | 782 |
| Sap | Bw\/4hana | 100 |
| Sap | Bw\/4hana | 200 |
References
- https://launchpad.support.sap.com/#/notes/2983367Permissions Required
- https://launchpad.support.sap.com/#/notes/2983367Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26838?
How severe is CVE-2020-26838?
How do I fix CVE-2020-26838?
Are you affected by CVE-2020-26838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
