CVE-2020-6230 is a code injection vulnerability affecting SAP OrientDB, version 3.0. An authenticated attacker with script execute/write permissions can inject and execute malicious code, gaining control over the application's behavior. This vulnerability carries a CVSS score of 7.2 (HIGH), indicating a network-based attack with low complexity, requiring high privileges, and leading to high impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:sap:orientdb:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.