CVE-2020-6306: Low severity SAP Leasing vulnerability
Missing authorization check in a transaction within SAP Leasing (update provided in SAPAPPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Patch SAP_APPL 6.18 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in EA-APPL 6.0 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in 6.02 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in 6.03 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in 6.04 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in 6.05 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in 6.06 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in 6.16 - Upgrade
Upgrade
SAP Leasingto a version that resolves this vulnerability.Fixed in 6.17
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6306?
CVE-2020-6306 has been assigned a medium severity rating due to missing authorization checks.
How do I fix CVE-2020-6306?
To address CVE-2020-6306, apply the updates provided in SAP_APPL versions 6.18, EA-APPL 6.0, or their subsequent releases.
What versions of SAP Leasing are affected by CVE-2020-6306?
CVE-2020-6306 affects SAP Leasing versions 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, and 6.17.
What causes CVE-2020-6306?
CVE-2020-6306 is caused by a missing authorization check in a transaction within SAP Leasing.
Is there a workaround for CVE-2020-6306?
There are no official workarounds for CVE-2020-6306; applying the recommended updates is necessary to mitigate the vulnerability.