Missing Authorization Check in SAP Treasury and Risk Management: Contract Number Selection Vulnerability

Missing Authorization Check in SAP Treasury and Risk Management: Contract Number Selection Vulnerability

CVE-2020-6204 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing Authorization Check.

Learn more about our Web Application Penetration Testing UK.