CVE-2020-6235

HIGH

SAP Solution Manager <7.2 - Missing Authentication

Title source: llm
STIX 2.1

Description

SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2906994

Scores

CVSS v3 8.6
EPSS 0.0038
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (1)
sap/solution_manager 7.2
Published Apr 14, 2020
Tracked Since Feb 18, 2026