PT-2020-5976 · Sap · Sap Banking Services

Published

2020-08-11

·

Updated

2020-08-14

·

CVE-2020-6298

CVSS v2.0

8.7

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions SAP Banking Services versions 400 through 500
Description The issue is related to a missing authorization check in the Generic Market Data component, allowing an unauthorized user to access and modify protected Business Partner Generic Market Data and related key figure values. This could potentially lead to the disclosure and integrity compromise of sensitive information.
Recommendations For versions 400 through 500, apply the necessary patches or updates to include authorization checks for Generic Market Data access and modifications. As a temporary workaround, consider restricting access to the Generic Market Data component until a patch is available. Restrict access to sensitive Business Partner data to minimize the risk of exploitation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02168
CVE-2020-6298

Affected Products

Sap Banking Services