Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6209 Missing Authorization check in SAP Disclosure Management, SAP security note 2858044

SAP Note 2858044
High priority

SAP security note 2858044, “[CVE-2020-6209] Missing Authorization check in SAP Disclosure Management”, released on March 10, 2020. Below are the symptom, SAP recommended solution and the affected software components.

ComponentEnterprise Performance Management > SAP Disclosure Management (DM) > DM core functionalities
PriorityCorrection with high priority
StatusReleased for Customer
Released onMarch 10, 2020

Description

Symptom

SAP Disclosure Management does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This vulnerability allows an attacker to abuse functionality restricted to specific user groups, and to read, modify, or delete restricted data.

Solution

To address this vulnerability, you need to manually install SAP Disclosure Management 10.1 Stack 1500 or later. The latest downloads are available via the SAP ONE Support Launchpad.

CVSS

Score 7.5 Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected components

  • SAP Disclosure Management 10.1 earlier than Stack 1500

Full note on SAP: SAP Support Launchpad note 2858044

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More