ZeroHour

CVE-2020-6204

CVSS 3.1
4.3 medium
EPSS
<1%p48
Published
()
Modified
Description

The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.

Vendors
sap
Products
treasury and risk management \(ea-finserv\), treasury and risk management \(s4core\)
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.