Authorization Bypass Vulnerability in SAP ERP HCM Travel Management
CVE-2020-6301
5.4MEDIUM
What is CVE-2020-6301?
SAP ERP HCM Travel Management versions 600 through 608 are susceptible to an authorization bypass due to a missing authorization check. This vulnerability allows an authenticated but unauthorized attacker to read, modify, and settle trips within the application, leading to potential privilege escalation.
Affected Version(s)
SAP ERP (HCM Travel Management) < 600 < 600
SAP ERP (HCM Travel Management) < 602 < 602
SAP ERP (HCM Travel Management) < 603 < 603