PT-2020-5153 · Sap · Sap Erp

Published

2020-08-12

·

Updated

2020-08-13

·

CVE-2020-6301

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP ERP (HCM Travel Management) versions 600 through 608
Description The issue is related to a missing authorization check, allowing an authenticated but unauthorized attacker to read, modify, and settle trips. This can result in an escalation of privileges. The vulnerability is associated with the SAP ERP HCM component and can be exploited by a remote attacker to elevate their privileges.
Recommendations For SAP ERP (HCM Travel Management) versions 600 through 608, consider implementing additional authorization checks to restrict access to sensitive functions, such as trip management, until a formal fix is available. As a temporary workaround, restrict access to the travel management module to minimize the risk of exploitation.

Fix

Missing Authorization

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05760
BDU:2020-05778
CVE-2020-6301

Affected Products

Sap Erp