Files
CVEs-PoC/2020/CVE-2020-6307.md
T
2024-05-25 21:48:12 +02:00

18 lines
763 B
Markdown

### [CVE-2020-6307](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6307)
![](https://img.shields.io/static/v1?label=Product&message=Automated%20Note%20Search%20Tool%20(SAP%20Basis)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C7.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Missing%20Authorization%20Check&color=brighgreen)
### Description
Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information.
### POC
#### Reference
- https://launchpad.support.sap.com/#/notes/2863397
#### Github
No PoCs found on GitHub currently.