CVE-2020-26838
Last modified
CVE-2020-26838 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any user interaction. It is possible to craft a request which will result in the execution of Operating System commands leading to Code Injection vulnerability which could completely compromise the confidentiality, integrity and availability of the server and any data or other applications running on it.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Warehouse | 700 |
| Sap | Business Warehouse | 701 |
| Sap | Business Warehouse | 702 |
| Sap | Business Warehouse | 731 |
| Sap | Business Warehouse | 740 |
| Sap | Business Warehouse | 750 |
| Sap | Business Warehouse | 751 |
| Sap | Business Warehouse | 752 |
| Sap | Business Warehouse | 753 |
| Sap | Business Warehouse | 754 |
| Sap | Business Warehouse | 755 |
| Sap | Business Warehouse | 782 |
| Sap | Bw\/4hana | 100 |
| Sap | Bw\/4hana | 200 |
References
- https://launchpad.support.sap.com/#/notes/2983367Permissions Required
- https://launchpad.support.sap.com/#/notes/2983367Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26838?
How severe is CVE-2020-26838?
How do I fix CVE-2020-26838?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-26831SAP BusinessObjects BI Platform (Crystal Report), versions -…9.6
- CVE-2020-26832SAP AS ABAP (SAP Landscape Transformation), versions - 2011_…7.6
- CVE-2020-26834SAP HANA Database, version - 2.0, does not correctly validat…5.4
- CVE-2020-26835SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 7…6.1
- CVE-2020-26836SAP Solution Manager (Trace Analysis), version - 720, allows…6.1
- CVE-2020-26837SAP Solution Manager 7.2 (User Experience Monitoring), versi…9.1
- CVE-2020-26839Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-2684Vulnerability in the Oracle FLEXCUBE Universal Banking produ…6.5
- CVE-2020-26840Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-26841Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-26842Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-26843Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2020-26838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
