cbcvebase.
CVE-2020-6273
published 2020-08-12

CVE-2020-6273: SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.

Affected

4 ranges
VendorProductVersion rangeFixed in
saps_4_hana_fiori_ui_for_general_ledger_accounting
saps_4_hana_fiori_ui_for_general_ledger_accounting
sap_sesap_s_4_hana< 103103
sap_sesap_s_4_hana< 104104