First published: Tue Jan 14 2020(Updated: )
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17).
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Leasing | =6.0 | |
SAP Leasing | =6.02 | |
SAP Leasing | =6.03 | |
SAP Leasing | =6.04 | |
SAP Leasing | =6.05 | |
SAP Leasing | =6.06 | |
SAP Leasing | =6.16 | |
SAP Leasing | =6.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6306 has been assigned a medium severity rating due to missing authorization checks.
To address CVE-2020-6306, apply the updates provided in SAP_APPL versions 6.18, EA-APPL 6.0, or their subsequent releases.
CVE-2020-6306 affects SAP Leasing versions 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, and 6.17.
CVE-2020-6306 is caused by a missing authorization check in a transaction within SAP Leasing.
There are no official workarounds for CVE-2020-6306; applying the recommended updates is necessary to mitigate the vulnerability.