Authorization Vulnerability in SAP Automated Note Search Tool
CVE-2020-6307
4.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 January 2020
Summary
The Automated Note Search Tool in various SAP Basis versions lacks adequate authorization checks. This flaw can potentially allow unauthorized users to access and read sensitive information, posing a significant security risk. Administrators are advised to assess their systems for this issue and implement necessary remediations to safeguard sensitive data.
Affected Version(s)
Automated Note Search Tool (SAP Basis) < 7.0 < 7.0
Automated Note Search Tool (SAP Basis) < 7.01 < 7.01
Automated Note Search Tool (SAP Basis) < 7.02 < 7.02
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved