PT-2020-16508 · Sap · Sap Solution Manager
Published
2020-11-10
·
Updated
2021-07-21
·
CVE-2020-26823
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Solution Manager (JAVA stack) version 7.20
Description
The issue allows an unauthenticated attacker to compromise the system due to missing authorization checks in the Upgrade Diagnostics Agent Connection Service. This has an impact on the integrity and availability of the service.
Recommendations
For SAP Solution Manager (JAVA stack) version 7.20, update to a version that includes the necessary authorization checks in the Upgrade Diagnostics Agent Connection Service to prevent unauthorized access. As a temporary workaround, consider restricting access to the Upgrade Diagnostics Agent Connection Service until a patch is available.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Solution Manager