René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

178 lines
5.5 KiB
JSON

{
"id": "CVE-2020-6307",
"sourceIdentifier": "cna@sap.com",
"published": "2020-01-14T18:15:12.180",
"lastModified": "2021-07-21T11:39:23.747",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive information."
},
{
"lang": "es",
"value": "Automated Note Search Tool (actualizaci\u00f3n proporcionada en SAP Basis versiones 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 y 7.54), no realiza suficientes comprobaciones de autorizaci\u00f3n conllevando a la lectura de informaci\u00f3n confidencial."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
],
"cvssMetricV30": [
{
"source": "cna@sap.com",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "49E9E5C3-C582-4294-A33E-5B54EC5A1046"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.01:*:*:*:*:*:*:*",
"matchCriteriaId": "D262D407-99E0-40B4-B57D-B8E693795368"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.02:*:*:*:*:*:*:*",
"matchCriteriaId": "5048545D-7872-4EB9-AA97-557944999BB6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.31:*:*:*:*:*:*:*",
"matchCriteriaId": "1AC2D764-A795-4FBC-95AF-D212B8E51991"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.40:*:*:*:*:*:*:*",
"matchCriteriaId": "B469CB1A-3AF3-4824-A185-A46A63DBABBE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.50:*:*:*:*:*:*:*",
"matchCriteriaId": "56852389-A9A8-42DB-A471-10C1990502FF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.51:*:*:*:*:*:*:*",
"matchCriteriaId": "594CB284-78FF-491F-BAF6-390E7D4D5DBE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.52:*:*:*:*:*:*:*",
"matchCriteriaId": "F7ACA030-9C6A-47D3-A7D9-899753870241"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.53:*:*:*:*:*:*:*",
"matchCriteriaId": "893979E3-40EB-4847-A39B-F548F3000F89"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:basis:7.54:*:*:*:*:*:*:*",
"matchCriteriaId": "977F2126-AB92-47D0-B7D4-314D468AC497"
}
]
}
]
}
],
"references": [
{
"url": "https://launchpad.support.sap.com/#/notes/2863397",
"source": "cna@sap.com",
"tags": [
"Permissions Required"
]
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533671771",
"source": "cna@sap.com",
"tags": [
"Vendor Advisory"
]
}
]
}