CVE-2020-6311
Published: Sep 9, 2020
Modified: Aug 4, 2024
CVSS v3.0
6.5
Description
Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorization checks, that may cause a system administrator to create incorrect authorization proposals. This may result in privilege escalation and may expose restricted banking data.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | BANKING SERVICES FROM SAP 9.0(Bank Analyzer) | affected < 500 |
SAP SE | S/4HANA FIN PROD SUBLDGR | affected < 100 |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now