CVE-2020-6301: SAP Hcm Travel Management

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check.

Affected products

  • SAP Hcm Travel Management: version 600 only; version 602 only; version 603 only; version 604 only; version 605 only; version 606 only; …

Published 2020-08-12. Last modified 2026-06-17.