Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6301 Missing Authorization check in SAP ERP (HCM Travel Management), SAP security note 2949196

SAP Note 2949196

SAP security note 2949196, "[CVE-2020-6301] Missing Authorization check in SAP ERP (HCM Travel Management)". Below are the symptom and SAP recommended solution.

Description

Symptom

UPDATE 13th October 2020: This note has been re-released with updated 'validity', and 'Support Packages & Patches' information.

SAP ERP's HCM Travel Management trip accounting allows an authenticated but unauthorized attacker to read, modify, and settle trips, resulting in escalation of privileges.

Solution

The affected functions have now been enforced to properly check access restrictions. Please implement the correction instructions.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected components

  • EA-HRGXX versions 600 to 608

Full note on SAP: SAP Support Launchpad note 2949196

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More