CVE-2020-6258
CVE-2020-6258
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 May 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
SAP SE · SAP Identity ManagementWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →