CVE-2020-6364
CRITICALSAP Solution Manager/Focused Run <10.7 - Code Injection
Title source: llmDescription
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.
Exploits (1)
References (4)
Scores
CVSS v3
10.0
EPSS
0.2064
EPSS Percentile
95.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (4)
sap/introscope_enterprise_manager
9.7
sap/introscope_enterprise_manager
10.1
sap/introscope_enterprise_manager
10.5
sap/introscope_enterprise_manager
10.7
Published
Oct 15, 2020
Tracked Since
Feb 18, 2026