PT-2020-16520 · Sap · Sap Solution Manager

Gonzalo Roisman

+1

·

Published

2020-12-09

·

Updated

2021-06-17

·

CVE-2020-26837

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP Solution Manager 7.2 (User Experience Monitoring) version 7.2
Description The issue allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability. This can compromise confidentiality by exposing elements of the file system, partially compromise integrity by allowing the modification of some configurations, and partially compromise availability by making certain services unavailable.
Recommendations For SAP Solution Manager 7.2 (User Experience Monitoring) version 7.2, consider restricting the upload of scripts to prevent exploitation of the path traversal vulnerability until a patch is available. As a temporary workaround, limit access to sensitive configurations and services to minimize the risk of modification or unavailability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26837

Affected Products

Sap Solution Manager