PT-2020-19051 · Sap · Sap Master Data Governance

Published

2020-05-12

·

Updated

2020-05-15

·

CVE-2020-6256

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions SAP Master Data Governance versions 748 through 804
Description The issue allows users to display change request details without having the required authorizations due to a Missing Authorization Check.
Recommendations For versions 748 through 804, apply the necessary authorization checks to ensure that users can only access change request details with the required permissions.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6256

Affected Products

Sap Master Data Governance