CVE-2020-6204

4.3MEDIUM

Summary

The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.

Affected Version(s)

SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV) < 600 < 600

SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV) < 603 < 603

SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV) < 604 < 604

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.