Authorization Vulnerability in SAP Automated Note Search Tool
CVE-2020-6307

4.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 January 2020

Summary

The Automated Note Search Tool in various SAP Basis versions lacks adequate authorization checks. This flaw can potentially allow unauthorized users to access and read sensitive information, posing a significant security risk. Administrators are advised to assess their systems for this issue and implement necessary remediations to safeguard sensitive data.

Affected Version(s)

Automated Note Search Tool (SAP Basis) < 7.0 < 7.0

Automated Note Search Tool (SAP Basis) < 7.01 < 7.01

Automated Note Search Tool (SAP Basis) < 7.02 < 7.02

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.