CVE-2020-26837
CVE-2020-26837
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.5EPSS 1.9%KEV nãoPoC —Patch —
Lifecycle
Dec 09, 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially compromise availability by making certain services unavailable.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Affected products
SAP SE · SAP Solution Manager (User Experience Monitoring)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →