CVE-2020-6273 Information
Feb 14, 2021
cve
Description
SAP S/4 HANA (Fiori UI for General Ledger Accounting) versions 103 104 does not perform necessary authorization checks for an authenticated user working with attachment service allowing the attacker to delete attachments due to Missing Authorization Check.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Reference
https://launchpad.support.sap.com//notes/2885671 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Share on: