CVE-2020-6268: High severity sap erp (ea-finserv) vulnerability
Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to Missing Authorization Check.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6268?
CVE-2020-6268 has a high severity rating due to the lack of proper authorization checks, allowing unauthorized access to sensitive information.
How do I fix CVE-2020-6268?
To fix CVE-2020-6268, apply the latest security patch provided by SAP for the affected EA-FINSERV and S4CORE versions.
What kind of data can be accessed due to CVE-2020-6268?
CVE-2020-6268 allows an attacker to view and tamper with restricted financial reporting data.
Which versions are affected by CVE-2020-6268?
CVE-2020-6268 affects EA-FINSERV versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104.
How can I determine if my SAP system is vulnerable to CVE-2020-6268?
You can determine if your SAP system is vulnerable to CVE-2020-6268 by checking the installed versions against the known affected versions.