Missing Authorization Check in SAP Adaptive Server Enterprise
CVE-2020-6259

6.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 May 2020

Summary

In certain configurations, SAP Adaptive Server Enterprise versions 15.7 and 16.0 are susceptible to a vulnerability that allows attackers to access confidential information. This situation arises due to a missing authorization check, which could lead to unauthorized data exposure. Organizations using affected versions must implement security measures to mitigate the risk and protect sensitive data.

Affected Version(s)

SAP Adaptive Server Enterprise < 15.7 < 15.7

SAP Adaptive Server Enterprise < 16.0 < 16.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.