← Back

CVE-2020-6316

nvd nist
Published: Nov 10, 2020Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

Affected (14)

Products: Sap: Erp, S/4hana
2 products
Erp
S/4hana
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 600
Version 602
Version 603
Version 604
Version 605
Version 606
Version 616
Version 617
Version 618
Sap
Version 100
Version 101
Version 102
Version 103
Version 104

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.