← Vulnerability feed

Vulnerability record · CVE-2020-6212 · published 24 April 2020

CVE-2020-6212: Sap erp missing authorization vulnerability

Sap · Erp

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax reports, due to Missing Authorization Check.

5.4 CVSS 3.1 Medium EPSS 0.65% · top 50.7% CWE-862 · Missing authorization
5.4CVSS 3.1 base score, v2 5.5
0.65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification of some tax reports, due to Missing Authorization Check.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-6212 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-0488Sap netweaver application server abap missing authorization vulnerabilityAn authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…EPSS 0.51%8.8CVE-2021-38176Sap landscape transformation sql injection vulnerabilityDue to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution…EPSS 1.3%8.8CVE-2020-6188Sap erp missing authorization vulnerabilityVAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (…EPSS 0.68%8.1CVE-2022-22530Sap s\/4hana vulnerabilityThe F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…EPSS 0.94%8.1CVE-2022-22531Sap s\/4hana vulnerabilityThe F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…EPSS 0.85%6.5CVE-2023-24524Sap s\/4hana missing authorization vulnerabilitySAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalatio…EPSS 0.52%6.5CVE-2022-31589Sap erp financial accounting incorrect authorization vulnerabilityDue to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than need…EPSS 0.66%6.5CVE-2022-22542Sap s\/4hana information exposure vulnerabilityS/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2020-6212), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.