High severity7.2NVD Advisory· Published May 12, 2020· Updated Jun 17, 2026
CVE-2020-6248
CVE-2020-6248
Description
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.
Affected products
3- cpe:2.3:a:sap:adaptive_server_enterprise_backup_server:16.0:*:*:*:*:*:*:*
- Range: 16.0
- SAP SE/SAP Adaptive Server Enterprise (Backup Server)v5Range: < 16.0
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.