CVE-2020-6298
SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Market Data (GMD) and change related GMD key figure values, due to Missing Authorization Check.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Market Data (GMD) and change related GMD key figure values, due to Missing Authorization Check.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- sap/generic market data
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2939685Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2939685Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.