First published: Wed Sep 09 2020(Updated: )
Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version ? 100, does not correctly perform necessary authorization checks for an authenticated user due to Improper Authorization checks, that may cause a system administrator to create incorrect authorization proposals. This may result in privilege escalation and may expose restricted banking data.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Bank Analyzer | =500 | |
Sap S\/4hana For Financial Products Subledger | =100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-6311 is classified as high due to its potential impact on authorization checks.
To fix CVE-2020-6311, apply the latest patches and updates provided by SAP for affected products.
CVE-2020-6311 affects SAP Bank Analyzer version 500 and SAP S/4HANA for financial products subledger version 100.
The impact of CVE-2020-6311 may allow an attacker to escalate privileges due to improper authorization checks.
Organizations using SAP Bank Analyzer 500 or SAP S/4HANA for financial products subledger 100 should be concerned about CVE-2020-6311.