Vulnerabilities > CVE-2020-6250 - Unspecified vulnerability in SAP Adaptive Server Enterprise 16.0

047910
CVSS 6.8 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
sap

Summary

SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read system administrator password leading to Information Disclosure. This could help the attacker to read/write any data and even stop the server like an administrator.

Vulnerable Configurations

Part Description Count
Application
Sap
1

The Hacker News

idTHN:54B521E08BF332B06621B81176A8E99F
last seen2020-06-03
modified2020-06-03
published2020-06-03
reporterThe Hacker News
sourcehttps://thehackernews.com/2020/06/newly-patched-sap-ase-flaws-could-let.html
titleNewly Patched SAP ASE Flaws Could Let Attackers Hack Database Servers