CVE-2020-6207
SAP Solution Manager Missing Authentication for Critical Function Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
YesDecision
Descriptions
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
SAP Solution Manager (User Experience Monitoring), versión 7.2, debido a una Falta de Comprobación de Autenticación no realiza ninguna autenticación para un servicio, resultando en un compromiso completo de todos los SMDAgents conectados al Solution Manager.
A malicious unauthenticated user could abuse the lack of authentication check on SAP Solution Manager User-Experience Monitoring web service, allowing them to remotely execute commands in all hosts connected to the targeted SolMan through these SMD Agents. Affected versions include SAP Solution Manager SP004 Patch 0011 and lower, SP005 Patch 0012 and lower, SP006 Patch 0013 and lower, SP007 Patch 0019 and lower, SP008 Patch 0015 and lower, SP009 Patch 0007 and lower, SP010 Patch 0001 and lower, and SP011 Patch 0003 and lower.
SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2020-01-08 CVE Reserved
- 2020-03-10 CVE Published
- 2021-03-26 First Exploit
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2024-12-29 EPSS Updated
- 2025-01-29 CVE Updated
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (10)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305 | 2021-06-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Solution Manager Search vendor "Sap" for product "Solution Manager" | 7.20 Search vendor "Sap" for product "Solution Manager" and version "7.20" | - |
Affected
|