Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-6204


The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.


Published

2020-03-10T21:15:14.527

Last Modified

2024-11-21T05:35:17.640

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap treasury_and_risk_management_\(ea-finserv\) 600 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 603 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 604 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 605 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 606 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 616 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 617 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 618 Yes
Application sap treasury_and_risk_management_\(ea-finserv\) 800 Yes
Application sap treasury_and_risk_management_\(s4core\) 101 Yes
Application sap treasury_and_risk_management_\(s4core\) 102 Yes
Application sap treasury_and_risk_management_\(s4core\) 103 Yes
Application sap treasury_and_risk_management_\(s4core\) 104 Yes

References