PT-2020-5976 · Sap · Sap Banking Services
Published
2020-08-11
·
Updated
2020-08-14
·
CVE-2020-6298
CVSS v2.0
8.7
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
SAP Banking Services versions 400 through 500
Description
The issue is related to a missing authorization check in the Generic Market Data component, allowing an unauthorized user to access and modify protected Business Partner Generic Market Data and related key figure values. This could potentially lead to the disclosure and integrity compromise of sensitive information.
Recommendations
For versions 400 through 500, apply the necessary patches or updates to include authorization checks for Generic Market Data access and modifications.
As a temporary workaround, consider restricting access to the Generic Market Data component until a patch is available.
Restrict access to sensitive Business Partner data to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Banking Services