8.1

CVE-2020-6268

Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to Missing Authorization Check.

Data is provided by the National Vulnerability Database (NVD)
SAPErp (ea-finserv) Version600
SAPErp (ea-finserv) Version603
SAPErp (ea-finserv) Version604
SAPErp (ea-finserv) Version605
SAPErp (ea-finserv) Version606
SAPErp (ea-finserv) Version616
SAPErp (ea-finserv) Version617
SAPErp (ea-finserv) Version618
SAPErp (ea-finserv) Version800
SAPErp (s4core) Version101
SAPErp (s4core) Version102
SAPErp (s4core) Version103
SAPErp (s4core) Version104
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.17% 0.343
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:P/I:P/A:N
cna@sap.com 5.4 2.8 2.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.