CVE-2020-6256
 
Severity Score
4.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check.
SAP Master Data Governance, versiones - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, permite a usuarios mostrar los detalles de las peticiones de cambio sin tener las autorizaciones requeridas, debido a una Falta de ComprobaciĆ³n de AutorizaciĆ³n.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-01-08 CVE Reserved
- 2020-05-12 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 | 2020-05-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 748 Search vendor "Sap" for product "Master Data Governance" and version "748" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 749 Search vendor "Sap" for product "Master Data Governance" and version "749" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 750 Search vendor "Sap" for product "Master Data Governance" and version "750" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 751 Search vendor "Sap" for product "Master Data Governance" and version "751" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 752 Search vendor "Sap" for product "Master Data Governance" and version "752" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 800 Search vendor "Sap" for product "Master Data Governance" and version "800" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 801 Search vendor "Sap" for product "Master Data Governance" and version "801" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 802 Search vendor "Sap" for product "Master Data Governance" and version "802" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 803 Search vendor "Sap" for product "Master Data Governance" and version "803" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Master Data Governance Search vendor "Sap" for product "Master Data Governance" | 804 Search vendor "Sap" for product "Master Data Governance" and version "804" | - |
Affected
|