CVE-2020-6209Missing Authorization in SE SAP Disclosure Management

Severity
7.5HIGHNVD
EPSS
0.4%
top 38.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMay 24

Description

SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Check.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-frq6-rwpv-5f3j: SAP Disclosure Management, version 102022-05-24
CVEList
CVE-2020-6209: SAP Disclosure Management, version 102020-03-10
CVE-2020-6209 — Missing Authorization | cvebase