CVE-2020-6214 Information

Description

SAP S/4HANA (Financial Products Subledger) version 100 uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects exploitation of the vulnerability would allow an authenticated attacker to view change or delete data thereby preventing the proper segregation of duties in the system.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Reference

https://launchpad.support.sap.com//notes/2897612 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

4.7

Share on: