« Volver al listado

CVE-2020-6249

Estado: ModificadaAlta (8.8)—

The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-6249",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.1
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP Master Data Governance (S4CORE)",
          "versions": [
            {
              "status": "affected",
              "version": "< 101"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP Master Data Governance (S4FND)",
          "versions": [
            {
              "status": "affected",
              "version": "< 102"
            },
            {
              "status": "affected",
              "version": "< 103"
            },
            {
              "status": "affected",
              "version": "< 104"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP Master Data Governance (SAP_BS_FND)",
          "versions": [
            {
              "status": "affected",
              "version": "< 748"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-05-12T18:15:14.257",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2908560",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2908560",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection."
    },
    {
      "lang": "es",
      "value": "El uso de un reporte del backend de administración dentro de SAP Master Data Governance, versiones - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; permite al atacante ejecutar consultas de base de datos diseñadas, exponiendo la base de datos del backend, conllevando a una Inyección SQL."
    }
  ],
  "lastModified": "2026-06-17T03:22:56.613",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:master_data_governance_\\(s4core\\):101:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6DB70C8-C5F7-4A88-AAE5-196189D996A4"
            },
            {
              "criteria": "cpe:2.3:a:sap:master_data_governance_\\(s4fnd\\):102:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B31029A2-255E-483A-B36F-582E1A197E34"
            },
            {
              "criteria": "cpe:2.3:a:sap:master_data_governance_\\(s4fnd\\):103:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9A72DEF-893B-49A3-91AB-39AA0B9E86E8"
            },
            {
              "criteria": "cpe:2.3:a:sap:master_data_governance_\\(s4fnd\\):104:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D10559F-3D6D-43B4-9ACE-96C94976FCAB"
            },
            {
              "criteria": "cpe:2.3:a:sap:master_data_governance_\\(sap_bs_fnd\\):748:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE06CAB7-D789-4C0F-B4B0-449FDD51B295"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}