CVE-2020-6301 describes a Missing Authorization Check vulnerability in SAP ERP HCM Travel Management, affecting versions 600 through 608. An authenticated but unauthorized attacker can exploit this flaw to read, modify, and settle travel-related data, leading to an escalation of privileges. With a CVSS score of 8.1 (High), this vulnerability is network-exploitable with low attack complexity and no user interaction, posing a significant risk to confidentiality and integrity. While no public exploit code, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion or media coverage, organizations should still prioritize patching due to the potential for unauthorized access and data manipulation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
600CPE matchmatch criteria | cpe:2.3:a:sap:hcm_travel_management:600:*:*:*:*:*:*:* | ||
602CPE matchmatch criteria | cpe:2.3:a:sap:hcm_travel_management:602:*:*:*:*:*:*:* | ||
603CPE matchmatch criteria | cpe:2.3:a:sap:hcm_travel_management:603:*:*:*:*:*:*:* | ||
604CPE matchmatch criteria | cpe:2.3:a:sap:hcm_travel_management:604:*:*:*:*:*:*:* | ||
605CPE matchmatch criteria | cpe:2.3:a:sap:hcm_travel_management:605:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.