Back to overview

CVE-2020-6364

CRITICAL
10.0
CVSS 3.0
Description
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.

Metadata

CVE ID
CVE-2020-6364
State
PUBLISHED
Assigner
sap
Reserved
2020-01-08 00:00 UTC
Published
2020-10-15 01:55 UTC
Last updated
2024-08-04 09:02 UTC
Vendor / Product
SAP SE / SAP Solution Manager (CA Introscope Enterprise Manager) and SAP Focused Run (CA Introscope Enterprise Manager)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
SAP SE SAP Solution Manager (CA Introscope Enterprise Manager) and SAP Focused Run (CA Introscope Enterprise Manager) < WILY_INTRO_ENTERPRISE 9.7, < 10.1, < 10.5, < 10.7
Weakness (CWE)
CWESourceDescription
cna Code Injection
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview