Authorization Flaw in SAP S/4HANA Financial Products Subledger
CVE-2020-6214
4.7MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 April 2020
What is CVE-2020-6214?
The vulnerability in SAP S/4HANA Financial Products Subledger arises from an incorrect authorization object utilized in certain reports. While other authorization objects may offer some level of protection, the exploitation of this flaw could allow an authenticated user to access, modify, or delete sensitive data. This compromises the essential segregation of duties within the system, leading to significant security concerns for organizations relying on this software.
Affected Version(s)
SAP S/4HANA (Financial Products Subledger) < 100