CVE-2020-6212: Medium severity sap erp localization for cee countries vulnerability
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax reports, due to Missing Authorization Check.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6212?
CVE-2020-6212 has a severe impact as it allows authenticated users to read or modify sensitive withholding tax reports without proper authorization.
How do I fix CVE-2020-6212?
To fix CVE-2020-6212, ensure that you apply the necessary patches provided by SAP in their security notes.
What versions of SAP are affected by CVE-2020-6212?
CVE-2020-6212 affects SAP ERP versions 607, 618, 730, and SAP S/4 HANA versions 100 to 104.
What is the impact of exploiting CVE-2020-6212?
Exploitation of CVE-2020-6212 could lead to unauthorized access and modification of localized tax reports.
Is there any workaround for CVE-2020-6212?
Currently, the best approach to mitigate the risks of CVE-2020-6212 is to apply the latest patches from SAP as no effective workaround is publicly available.