PT-2020-16494 · Sap · Sap Erp Client For E-Bilanz
Published
2020-11-10
·
Updated
2020-11-24
·
CVE-2020-26807
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SAP ERP Client for E-Bilanz version 1.0
Description
The issue concerns incorrect default filesystem permissions set in the installation folder of the SAP ERP Client for E-Bilanz, allowing anyone to modify the files in the folder.
Recommendations
For SAP ERP Client for E-Bilanz version 1.0, consider changing the default filesystem permissions in the installation folder to restrict access and prevent unauthorized modifications. As a temporary workaround, restrict access to the installation folder to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Erp Client For E-Bilanz