Vulnerability Description
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Basis | 7.0 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2863397Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533671771Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2863397Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533671771Vendor Advisory
FAQ
What is CVE-2020-6307?
CVE-2020-6307 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitiv...
How severe is CVE-2020-6307?
CVE-2020-6307 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6307?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Basis.