CVE-2020-6212

5.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
24 April 2020

Summary

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax reports, due to Missing Authorization Check.

Affected Version(s)

SAP ERP < 618 < 618

SAP ERP < 730 < 730

SAP ERP < EAPPLGLO 607 < EAPPLGLO 607

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.