Lucene search

K
cvelistSapCVELIST:CVE-2020-6362
HistoryOct 20, 2020 - 1:31 p.m.

CVE-2020-6362

2020-10-2013:31:51
sap
www.cve.org
3
sap
banking services
authorization
vulnerability
privilege escalation
segregation of duties
service interruptions
system unavailability

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

35.0%

SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to privilege escalation and violation in segregation of duties, which in turn could lead to Service interruptions and system unavailability for the victim and users of the component.

CNA Affected

[
  {
    "product": "SAP Banking Services",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 500"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

EPSS

0.001

Percentile

35.0%

Related for CVELIST:CVE-2020-6362