« Back to list

CVE-2020-6301

Status: ModifiedHigh (8.1)—

SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2020-6301",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP ERP (HCM Travel Management)",
          "versions": [
            {
              "status": "affected",
              "version": "< 600"
            },
            {
              "status": "affected",
              "version": "< 602"
            },
            {
              "status": "affected",
              "version": "< 603"
            },
            {
              "status": "affected",
              "version": "< 604"
            },
            {
              "status": "affected",
              "version": "< 605"
            },
            {
              "status": "affected",
              "version": "< 606"
            },
            {
              "status": "affected",
              "version": "< 607"
            },
            {
              "status": "affected",
              "version": "< 608"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-08-12T14:15:14.610",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2949196",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2949196",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check."
    },
    {
      "lang": "es",
      "value": "SAP ERP (HCM Travel Management), versiones: 600, 602, 603, 604, 605, 606, 607, 608, permite a un atacante autenticado pero no autorizado leer, modificar y liquidar viajes, resultando en una escalada de privilegios debido a una Falta de Comprobación de Autorización"
    }
  ],
  "lastModified": "2026-06-17T03:23:01.813",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:600:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5FBDACC-85FA-4561-BC46-071FF125F513"
            },
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:602:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2BBB3EB-28AF-49A1-AA51-5FFC3CBA592C"
            },
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:603:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24430EEB-FBDB-4676-AA0A-E30D04E142E0"
            },
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:604:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B43844D-9A18-4A9C-9F8A-47F40C7B5623"
            },
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:605:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E340868B-FC08-4641-AE6B-40E7A9F55510"
            },
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:606:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0734A2B1-5B0E-490A-B5D1-EDD564D17A5D"
            },
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:607:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0E31A95-FF37-4340-B5C4-D6C9BF5DE395"
            },
            {
              "criteria": "cpe:2.3:a:sap:hcm_travel_management:608:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E5F2AFC-358F-484D-932A-478C55C321B0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}