CVE-2020-6258

MEDIUM

SAP Identity Management <8.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2915429

Scores

CVSS v3 6.5
EPSS 0.0017
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-862
Status published
Products (1)
sap/identity_management 8.0
Published May 12, 2020
Tracked Since Feb 18, 2026