PT-2020-19065 · Sap · Sap Netweaver As Abap

Published

2020-06-10

·

Updated

2022-10-05

·

CVE-2020-6270

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS ABAP (Banking Services) versions 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E
Description The issue arises due to a missing authorization check, allowing an authenticated user to make unauthorized changes to individual conditions, potentially leading to incorrect prices.
Recommendations For SAP NetWeaver AS ABAP (Banking Services) versions 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, ensure that proper authorization checks are implemented to prevent malicious users from altering conditions and prices. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-6270

Affected Products

Sap Netweaver As Abap