cbcvebase.
CVE-2020-6199
published 2020-03-10

CVE-2020-6199: The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate…

medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization group can maintain any company certificate, leading to Missing Authorization Check.

Affected

9 ranges
VendorProductVersion rangeFixed in
saperp
sap_sesap_erp< 607607
sap_sesap_erp< 618618
sap_sesap_erp< 730730
sap_sesap_s_4hana< 100100
sap_sesap_s_4hana< 101101
sap_sesap_s_4hana< 102102
sap_sesap_s_4hana< 103103
sap_sesap_s_4hana< 104104