Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-6212


Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax reports, due to Missing Authorization Check.


Published

2020-04-24T23:15:11.670

Last Modified

2024-11-21T05:35:18.607

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap erp 607 Yes
Application sap erp 618 Yes
Application sap erp 730 Yes
Application sap s\/4hana 100 Yes
Application sap s\/4hana 101 Yes
Application sap s\/4hana 102 Yes
Application sap s\/4hana 103 Yes
Application sap s\/4hana 104 Yes

References