CVE-2020-6204
4.3MEDIUM
Key Information:
- Vendor
- SAP
- Status
- Vendor
- CVE Published:
- 10 March 2020
Summary
The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.
Affected Version(s)
SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV) < 600 < 600
SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV) < 603 < 603
SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV) < 604 < 604
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved