CVE-2020-6306 Information
Feb 14, 2021
cve
Description
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18 EA-APPL 6.0 6.02 6.03 6.04 6.05 6.06 6.16 and 6.17).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Reference
https://launchpad.support.sap.com//notes/2865348 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533671771
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
2.7
Share on: