CVE-2020-6307Incorrect Authorization in SE Automated Note Search Tool

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 53.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 24

Description

Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDsap/basis10 versions+9

🔴Vulnerability Details

2
GHSA
GHSA-6p9c-w66g-f5rf: Automated Note Search Tool (update provided in SAP Basis 72022-05-24
CVEList
CVE-2020-6307: Automated Note Search Tool (update provided in SAP Basis 72020-01-14
CVE-2020-6307 — Incorrect Authorization | cvebase