CVE-2020-6268
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to Missing Authorization Check.
Statutory Reporting de Insurance Companies en SAP ERP (EA-FINSERV versiones - 600, 603, 604, 605, 606, 616, 617, 618, 800 y S4CORE versiones 101, 102, 103, 104) no ejecuta las comprobaciones de autorización requeridas para un usuario autenticado, que permite a un atacante visualizar y manipular determinados datos restringidos conllevando a una Falta de Verificación de Autorización
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-08 CVE Reserved
- 2020-06-10 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 | 2020-06-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 600 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "600" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 603 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "603" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 604 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "604" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 605 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "605" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 606 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "606" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 616 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "616" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 617 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "617" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 618 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "618" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(ea-finserv\) Search vendor "Sap" for product "Erp \(ea-finserv\)" | 800 Search vendor "Sap" for product "Erp \(ea-finserv\)" and version "800" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(s4core\) Search vendor "Sap" for product "Erp \(s4core\)" | 101 Search vendor "Sap" for product "Erp \(s4core\)" and version "101" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(s4core\) Search vendor "Sap" for product "Erp \(s4core\)" | 102 Search vendor "Sap" for product "Erp \(s4core\)" and version "102" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(s4core\) Search vendor "Sap" for product "Erp \(s4core\)" | 103 Search vendor "Sap" for product "Erp \(s4core\)" and version "103" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Erp \(s4core\) Search vendor "Sap" for product "Erp \(s4core\)" | 104 Search vendor "Sap" for product "Erp \(s4core\)" and version "104" | - |
Affected
|