← Back

CVE-2020-6268

nvd nist
Published: Jun 10, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to Missing Authorization Check.

Affected (13)

2 products
Erp (ea Finserv)
Erp (s4core)
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 600
Version 603
Version 604
Version 605
Version 606
Version 616
Version 617
Version 618
Version 800
Sap
Version 101
Version 102
Version 103
Version 104

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.