CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-6364

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1360%
EPSS Percentile27.68th
Published2020年10月15日
Last Modified2024年11月21日

Vulnerability Description

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.

Affected Platforms (CPE)

📦
Sap

Introscope Enterprise Manager

= 9.7
📦
Sap

Introscope Enterprise Manager

= 10.1
📦
Sap

Introscope Enterprise Manager

= 10.5
📦
Sap

Introscope Enterprise Manager

= 10.7

References & Advisories

関連する脆弱性情報