VulnerabilityModified
CVE-2020-6198
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources.
CRITICAL 9.8EPSS 1.38%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.38% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306, CWE-319
- Affected
- sap/solution manager
- Source
- cna@sap.com
References
- https://launchpad.support.sap.com/#/notes/2845377Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2845377Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.