VulnerabilityModified
CVE-2020-6258
SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.
MEDIUM 6.5EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- sap/identity management
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2915429Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2915429Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.