Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6214

Опубликовано: 14 апр. 2020
Источник: nvd
CVSS3: 4.7
CVSS3: 4.7
CVSS2: 6.5
EPSS Низкий

Описание

SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data, thereby preventing the proper segregation of duties in the system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:s\/4hana:100:*:*:*:*:financial_products_subledger:*:*

EPSS

Процентиль: 42%
0.00201
Низкий

4.7 Medium

CVSS3

4.7 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-863
CWE-863

Связанные уязвимости

github
больше 3 лет назад

SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data, thereby preventing the proper segregation of duties in the system.

EPSS

Процентиль: 42%
0.00201
Низкий

4.7 Medium

CVSS3

4.7 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-863
CWE-863