Missing Authorization Check in SAP S/4 HANA Financial Products Subledger and Banking Services
CVE-2020-6233

4.3MEDIUM

Summary

In SAP S/4 HANA, specifically within the Financial Products Subledger and Banking Services, an issue exists that allows authenticated users to bypass essential authorization checks. This vulnerability enables these users to execute analysis reports without proper permissions, which can lead to a decline in system performance due to excessive resource consumption. It is crucial for organizations to secure their SAP environments against such risks to maintain operational integrity and ensure that user permissions are effectively enforced.

Affected Version(s)

SAP S/4 HANA (Financial Products Subledger and Banking Services) (FSAPPL) < 400 < 400

SAP S/4 HANA (Financial Products Subledger and Banking Services) (FSAPPL) < 450 < 450

SAP S/4 HANA (Financial Products Subledger and Banking Services) (FSAPPL) < 500 < 500

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.