Sap Treasury And Risk Management vulnerabilities
4 known vulnerabilities affecting sap/treasury_and_risk_management.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-6204MEDIUMCVSS 4.3v600v603+11 more2020-03-10
CVE-2020-6204 [MEDIUM] CWE-862 CVE-2020-6204: The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?version
The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.
nvd
CVE-2019-0383HIGHCVSS 8.8v1.01v1.02+2 more2019-12-17
CVE-2019-0383 [HIGH] CWE-863 CVE-2019-0383: Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02,
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
nvd
CVE-2019-0384HIGHCVSS 8.8v1.01v1.02+2 more2019-12-17
CVE-2019-0384 [HIGH] CWE-863 CVE-2019-0384: Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02,
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user identity.
nvd
CVE-2019-0280HIGHCVSS 8.8v6.0v6.03+7 more2019-05-14
CVE-2019-0280 [HIGH] CWE-862 CVE-2019-0280: SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0;
SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.
nvd