CVE-2020-6199: Medium severity SAP ERP vulnerability
The view FIMENAVCOMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAPFIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization group can maintain any company certificate, leading to Missing Authorization Check.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6199?
CVE-2020-6199 is classified as a high-severity vulnerability due to the lack of authorization checks.
What systems are affected by CVE-2020-6199?
CVE-2020-6199 affects SAP ERP version 607, and SAP S/4HANA versions 100 through 104.
How do I fix CVE-2020-6199?
To remediate CVE-2020-6199, implement the necessary authorization checks for the view FIMENAV_COMPCERT in your SAP system.
What type of attack does CVE-2020-6199 allow?
CVE-2020-6199 allows an attacker to access sensitive information without proper authorization.
Is there a workaround for CVE-2020-6199?
Yes, temporarily limiting access to the view FIMENAV_COMPCERT can serve as a workaround for CVE-2020-6199 until a full fix is implemented.