CVE-2020-6214
CVE-2020-6214
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.7EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Apr 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data, thereby preventing the proper segregation of duties in the system.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Affected products
SAP SE · SAP S/4HANA (Financial Products Subledger)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →