8.1
CVE-2020-6268
- EPSS 0.17%
- Veröffentlicht 10.06.2020 13:15:18
- Zuletzt bearbeitet 21.11.2024 05:35:24
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to Missing Authorization Check.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Erp (ea-finserv) Version600
SAP ≫ Erp (ea-finserv) Version603
SAP ≫ Erp (ea-finserv) Version604
SAP ≫ Erp (ea-finserv) Version605
SAP ≫ Erp (ea-finserv) Version606
SAP ≫ Erp (ea-finserv) Version616
SAP ≫ Erp (ea-finserv) Version617
SAP ≫ Erp (ea-finserv) Version618
SAP ≫ Erp (ea-finserv) Version800
SAP ≫ Erp (s4core) Version101
SAP ≫ Erp (s4core) Version102
SAP ≫ Erp (s4core) Version103
SAP ≫ Erp (s4core) Version104
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.17% | 0.343 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
cna@sap.com | 5.4 | 2.8 | 2.5 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.