CVE-2020-6369
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the…
Does this matter?
Lower severity and a low EPSS score (2.67%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of the service.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.67% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- sap/focused run · sap/solution manager
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/163159/SAP-Wily-Introscope-Enterprise-Default-Hard-Coded-Credentials.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/31Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2971638Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196Vendor Advisory
- http://packetstormsecurity.com/files/163159/SAP-Wily-Introscope-Enterprise-Default-Hard-Coded-Credentials.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/31Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2971638Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.