VYPR
Medium severity4.3NVD Advisory· Published Jan 14, 2020· Updated Jun 17, 2026

CVE-2020-6307

CVE-2020-6307

Description

Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.

Affected products

13
  • SAP/BASIS11 versions
    cpe:2.3:a:sap:basis:7.01:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:sap:basis:7.01:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.02:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.40:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.50:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.51:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.52:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.53:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.54:*:*:*:*:*:*:*
    • (no CPE)range: 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54
  • Range: 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54
  • SAP SE/Automated Note Search Tool (SAP Basis)v5
    Range: < 7.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.