CVE-2020-6364
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 6.41% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- sap/introscope enterprise manager
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/163153/SAP-Wily-Introscope-Enterprise-OS-Command-Injection.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/28Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2969828Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196Vendor Advisory
- http://packetstormsecurity.com/files/163153/SAP-Wily-Introscope-Enterprise-OS-Command-Injection.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/28Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2969828Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.