PT-2020-19135 · Sap · Sap Banking Services

Published

2020-10-20

·

Updated

2020-10-22

·

CVE-2020-6362

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SAP Banking Services version 500
Description The issue arises from the use of an incorrect authorization object in some reports, which could lead to privilege escalation and violation of segregation of duties. Although the affected reports are protected with other authorization objects, exploitation of this issue could result in service interruptions and system unavailability for the victim and users of the component.
Recommendations For SAP Banking Services version 500, consider reviewing and correcting the authorization objects used in the reports to prevent privilege escalation and ensure proper segregation of duties. As a temporary workaround, restrict access to the affected reports until the authorization objects are corrected.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6362

Affected Products

Sap Banking Services