SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect...
Vulnerability Description
SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data, thereby preventing the proper segregation of duties in the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-6214
Credits & Attribution
No credits recorded in the NVD database.
References
More from SAP SE
View All →Affected Vendor
SAP SE
View all reports →