CVE-2020-6362

MEDIUM

SAP Banking Services 500 - Privilege Escalation

Title source: llm
STIX 2.1

Description

SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to privilege escalation and violation in segregation of duties, which in turn could lead to Service interruptions and system unavailability for the victim and users of the component.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2953212

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 34.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-863
Status published
Products (1)
sap/banking_services 500
Published Oct 20, 2020
Tracked Since Feb 18, 2026