PT-2020-19011 · Sap · Sap Erp+1
Published
2020-04-24
·
Updated
2020-05-08
·
CVE-2020-6212
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP ERP versions 607 through 730
S/4 HANA versions 100 through 104
Description
The issue concerns the Egypt localized withholding tax reports in SAP systems, where the Clearing of Liabilities and Remittance Statement and Summary do not perform necessary authorization checks for an authenticated user. This allows the reading or modification of some tax reports due to a missing authorization check.
Recommendations
For SAP ERP versions 607 through 730, update to a version that includes the necessary authorization checks.
For S/4 HANA versions 100 through 104, update to a version that includes the necessary authorization checks.
As a temporary workaround, consider restricting access to the tax reports until a patch is available.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
S/4Hana
Sap Erp