CVE-2020-26808
Summary
| CVE | CVE-2020-26808 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-10 17:15:00 UTC |
| Updated | 2022-07-01 19:11:00 UTC |
| Description | SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Sap As Abapdmis | 2011_1_620 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_640 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_700 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_710 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_730 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_731 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_752 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2020 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_620 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_640 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_700 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_710 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_730 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_731 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2011_1_752 | All | All | All |
| Application | Sap | Sap As Abapdmis | 2020 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 101 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 102 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 103 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 104 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 105 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 101 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 102 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 103 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 104 | All | All | All |
| Application | Sap | Sap S4 Hanadmis | 105 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – November 2020 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required |
| SAP Application Server ABAP / ABAP Platform Code Injection / SQL Injection / Missing Authorization ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Full Disclosure: SEC Consult SA-20220518-0 :: Multiple Critical Vulnerabilities in SAP® Application Server, ABAP and ABAP® Platform (Different Software Components) | FULLDISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.