CVE-2020-6307: Medium severity SAP BASIS vulnerability
Published Jan 14, 2020
·Updated
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.
Affected Software
10 affected components
SAP BASIS=7.0
SAP BASIS=7.01
SAP BASIS=7.02
SAP BASIS=7.31
SAP BASIS=7.40
SAP BASIS=7.50
SAP BASIS=7.51
SAP BASIS=7.52
SAP BASIS=7.53
SAP BASIS=7.54
Event History
Jan 14, 2020
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2020-6307.
2
What software is affected by this vulnerability?
The SAP Basis software versions 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53, and 7.54 are affected.
3
What is the severity rating of CVE-2020-6307?
The severity rating of CVE-2020-6307 is medium (4.3).
4
What is the impact of this vulnerability?
This vulnerability allows unauthorized users to access sensitive information.
5
Where can I find more information about CVE-2020-6307?
You can find more information about CVE-2020-6307 at the following references: [link1](https://launchpad.support.sap.com/#/notes/2863397) and [link2](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533671771).