High priority
SAP security note 2858044, “[CVE-2020-6209] Missing Authorization check in SAP Disclosure Management”, released on March 10, 2020. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Disclosure Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This vulnerability allows an attacker to abuse functionality restricted to specific user groups, and to read, modify, or delete restricted data.
Solution
To address this vulnerability, you need to manually install SAP Disclosure Management 10.1 Stack 1500 or later. The latest downloads are available via the SAP ONE Support Launchpad.
CVSS
Score 7.5 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected components
- SAP Disclosure Management 10.1 earlier than Stack 1500
Full note on SAP: SAP Support Launchpad note 2858044
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
