CVE-2020-6198

CRITICAL

SAP Solution Manager <720 - Unauthenticated RCE

Title source: llm
STIX 2.1

Description

SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2845377

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319 CWE-306
Status published
Products (1)
sap/solution_manager 7.20
Published Mar 10, 2020
Tracked Since Feb 18, 2026