Sap Se Sap Treasury And Risk Management vulnerabilities
4 known vulnerabilities affecting sap_se/sap_treasury_and_risk_management.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-6204MEDIUMCVSS 4.3fixed in 600fixed in 603+11 more2020-03-10
CVE-2020-6204 [MEDIUM] CWE-862 CVE-2020-6204: The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?version
The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.
cvelistv5nvd
CVE-2019-0383HIGHCVSS 8.8fixed in 1.01fixed in 1.02+11 more2019-12-17
CVE-2019-0383 [HIGH] CWE-863 CVE-2019-0383: Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02,
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
cvelistv5nvd
CVE-2019-0384HIGHCVSS 8.8fixed in 1.01fixed in 1.02+11 more2019-12-17
CVE-2019-0384 [HIGH] CWE-863 CVE-2019-0384: Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02,
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user identity.
cvelistv5nvd
CVE-2019-0280HIGHCVSS 8.8fixed in 6.0fixed in 6.03+7 more2019-05-14
CVE-2019-0280 [HIGH] CWE-862 CVE-2019-0280: SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0;
SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.
cvelistv5nvd