First published: Wed Aug 12 2020(Updated: )
Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to access confidential system configuration information, that should otherwise be restricted, leading to Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Data Intelligence | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-6297.
The title of the vulnerability is 'Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence version - 3.0 allows attacker to access confidential system configuration information'.
The severity of CVE-2020-6297 is medium with a CVSS score of 4.4.
SAP Data Intelligence version 3.0 is affected by CVE-2020-6297.
An attacker can exploit CVE-2020-6297 by upgrading SAP Data Hub 2.7 to SAP Data Intelligence version 3.0 under certain conditions to gain access to confidential system configuration information.