4.3

CVE-2020-6316

SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPErp Version600
SAPErp Version602
SAPErp Version603
SAPErp Version604
SAPErp Version605
SAPErp Version606
SAPErp Version616
SAPErp Version617
SAPErp Version618
SAPS/4hana Version100
SAPS/4hana Version101
SAPS/4hana Version102
SAPS/4hana Version103
SAPS/4hana Version104
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.32
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
cna@sap.com 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.