« Volver al listado

CVE-2020-6188

Estado: ModificadaAlta (8.8)—

VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-6188",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.1
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP ERP (SAP_APPL)",
          "versions": [
            {
              "status": "affected",
              "version": "= 6.0"
            },
            {
              "status": "affected",
              "version": "= 6.02"
            },
            {
              "status": "affected",
              "version": "= 6.03"
            },
            {
              "status": "affected",
              "version": "= 6.04"
            },
            {
              "status": "affected",
              "version": "= 6.05"
            },
            {
              "status": "affected",
              "version": "= 6.06"
            },
            {
              "status": "affected",
              "version": "= 6.16"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP ERP (SAP_FIN)",
          "versions": [
            {
              "status": "affected",
              "version": "= 6.17"
            },
            {
              "status": "affected",
              "version": "= 6.18"
            },
            {
              "status": "affected",
              "version": "= 7.0"
            },
            {
              "status": "affected",
              "version": "= 7.20"
            },
            {
              "status": "affected",
              "version": "= 7.30"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP S/4 HANA (S4CORE)",
          "versions": [
            {
              "status": "affected",
              "version": "= 1.0"
            },
            {
              "status": "affected",
              "version": "= 1.01"
            },
            {
              "status": "affected",
              "version": "= 1.02"
            },
            {
              "status": "affected",
              "version": "= 1.03"
            },
            {
              "status": "affected",
              "version": "= 1.04"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-02-12T20:15:14.400",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2857511",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2857511",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check."
    },
    {
      "lang": "es",
      "value": "Los reportes de VAT Pro-Rata en SAP ERP (SAP_APPL versiones 600, 602, 603, 604, 605, 606, 616 y SAP_FIN versiones 617, 618, 700, 720, 730) y SAP S/4 HANA (versiones 100, 101, 102 , 103, 104), no realizan las comprobaciones de autorización necesarias para un usuario autenticado, conllevando a una Falta de Comprobación de Autorización."
    }
  ],
  "lastModified": "2026-06-17T03:22:50.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:erp:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "567E715A-39D9-4524-A60B-0A919A460D7D"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:1511:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02BC74F5-5560-4459-B712-5834DEB85B45"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:1610:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CDC5426-D2C1-430A-96AF-F25CE04A01A7"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:1709:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2F4BB0A-56DD-4A82-AB66-46C67A261287"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:1809:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB6E0D66-B1DF-4E65-9155-07C687C08046"
            },
            {
              "criteria": "cpe:2.3:a:sap:s\\/4_hana:1909:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "055B76F2-6B9F-475F-8244-E427DCB6B0F2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}