PT-2020-5153 · Sap · Sap Erp
Published
2020-08-12
·
Updated
2020-08-13
·
CVE-2020-6301
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SAP ERP (HCM Travel Management) versions 600 through 608
Description
The issue is related to a missing authorization check, allowing an authenticated but unauthorized attacker to read, modify, and settle trips. This can result in an escalation of privileges. The vulnerability is associated with the SAP ERP HCM component and can be exploited by a remote attacker to elevate their privileges.
Recommendations
For SAP ERP (HCM Travel Management) versions 600 through 608, consider implementing additional authorization checks to restrict access to sensitive functions, such as trip management, until a formal fix is available. As a temporary workaround, restrict access to the travel management module to minimize the risk of exploitation.
Fix
Missing Authorization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Erp