CyberSec.Space Logo
Back to CVE Browser

CVE-2020-6364

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1360%
EPSS Percentile27.68th
PublishedOct 15, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.

Affected Platforms (CPE)

πŸ“¦
Sap

Introscope Enterprise Manager

= 9.7
πŸ“¦
Sap

Introscope Enterprise Manager

= 10.1
πŸ“¦
Sap

Introscope Enterprise Manager

= 10.5
πŸ“¦
Sap

Introscope Enterprise Manager

= 10.7

References & Advisories

Related Vulnerabilities