VulnerabilityModified
CVE-2020-6259
Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information which would otherwise be restricted leading to Missing Authorization Check.
MEDIUM 6.5EPSS 0.77%
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information which would otherwise be restricted leading to Missing Authorization Check.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- sap/adaptive server enterprise
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2920548Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2920548Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.