CVE-2020-25563

CRITICAL

SapphireIMS 5.0 - Unauthenticated Remote Command Execution via RemoteMgmtTaskSave

Title source: llm
STIX 2.1

Description

In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature and not having a JSESSIONID.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0156
EPSS Percentile 72.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
sapphireims/sapphireims 5.0
Published Aug 11, 2021
Tracked Since Feb 18, 2026