CVE-2020-6297

MEDIUM

SAP Data Hub <3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to access confidential system configuration information, that should otherwise be restricted, leading to Information Disclosure.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2940823

Scores

CVSS v3 4.4
EPSS 0.0005
EPSS Percentile 16.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
sap/data_intelligence 3.0
Published Aug 12, 2020
Tracked Since Feb 18, 2026