CVE-2020-6270
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/06/2020
Last modified:
05/10/2022
Description
SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:netweaver_application_server_abap:75a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:75b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:75c:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:75d:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:75e:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:710:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:711:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:740:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:750:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:751:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:netweaver_application_server_abap:752:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



