CVE-2020-26808: SAP As Abap(dmis)

High severity, CVSS 7.2. EPSS: 3.1% chance of exploitation in the next 30 days.

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application.

Affected products

  • SAP SAP As Abap(dmis): version 2011_1_620 only; version 2011_1_640 only; version 2011_1_700 only; version 2011_1_710 only; version 2011_1_730 only; version 2011_1_731 only; …
  • SAP SAP s4 Hana(dmis): version 101 only; version 102 only; version 103 only; version 104 only; version 105 only

Published 2020-11-10. Last modified 2026-06-17.