Advisory
On 12.05.2020 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Adaptive Server Enterprise (ASE) .
SAP Note 2917273 addresses "[CVE-2020-6253] SQL Injection vulnerability in SAP Adaptive Server Enterprise (Web Services)" to prevent sql injection (read/write) with a high risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
Under certain conditions, SAP Adaptive Server Enterprise (ASE) Web Services allows an authenticated user to execute crafted database queries to elevate privileges of users in the system.Solution
The application input validation checks have been updated to prevent this type of attack.
- 8.8 [CVE-2020-6241] SQL Injection vulnerability in SAP Adaptive Server Enterprise
- 7.2 Update 1 to Note 2319506
- 7.2 [CVE-2018-2450] SQL Injection Vulnerability in SAP MaxDB/liveCache
- 5.4 SQL Injection in SAF-T Portugal
- 4.1 [CVE-2023-49581] SQL Injection vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform