← Vulnerability feed

Vulnerability record · CVE-2020-6318 · published 9 September 2020

CVE-2020-6318: Sap abap platform code injection vulnerability

Sap · Abap Platform

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.

7.2 CVSS 3.1 High EPSS 5.8% · top 7.1% CWE-94 · Code injection
7.2CVSS 3.1 base score, v2 6.5
5.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to take complete control of the products, including viewing, changing, or deleting data by injecting code into the working memory which is subsequently executed by the application. It can also be used to cause a general fault in the product, causing the products to terminate.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6318 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-44231Sap abap platform code injection vulnerabilityInternally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…EPSS 1.3%8.8CVE-2020-6296Sap abap platform vulnerabilitySAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject co…EPSS 1.3%7.2CVE-2024-22131Sap abap platform code injection vulnerabilityIn SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote executi…EPSS 1.1%5.8CVE-2020-6181Sap abap platform vulnerabilityUnder some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS ver…EPSS 0.78%5.4CVE-2023-29110Sap abap platform cross-site scripting vulnerabilityThe SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, applicati…EPSS 0.32%5.3CVE-2024-27900Sap abap platform missing authorization vulnerabilityDue to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of jo…EPSS 0.39%4.9CVE-2023-25615Sap abap platform sql injection vulnerabilityDue to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter …EPSS 0.55%4.6CVE-2023-29109Sap abap platform csv injection vulnerabilityThe SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, appl…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2020-6318), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.