Vulnerability Description
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Erp | 6.0 |
| Sap | S\/4 Hana | 1511 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2857511Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2857511Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812Vendor Advisory
FAQ
What is CVE-2020-6188?
CVE-2020-6188 is a vulnerability with a CVSS score of 8.8 (HIGH). VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform ne...
How severe is CVE-2020-6188?
CVE-2020-6188 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6188?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Erp, Sap S\/4 Hana.