CVE-2020-6298

HIGH

SAP Banking Services - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Market Data (GMD) and change related GMD key figure values, due to Missing Authorization Check.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2939685

Scores

CVSS v3 8.1
EPSS 0.0021
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-862
Status published
Products (3)
sap/generic_market_data 400
sap/generic_market_data 450
sap/generic_market_data 500
Published Aug 12, 2020
Tracked Since Feb 18, 2026