CVE-2020-26837
CVE-2020-26837
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.5EPSS 1.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
09 dic 2020Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially compromise availability by making certain services unavailable.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Productos afectados
SAP SE · SAP Solution Manager (User Experience Monitoring)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →