PT-2020-19032 · Sap · Sap Solution Manager
Published
2020-04-14
·
Updated
2022-04-06
·
CVE-2020-6235
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Solution Manager (Diagnostics Agent) version 7.2
Description
The issue is related to missing authentication in the Collector Simulator functionalities. This occurs because the authentication check is not performed, allowing unauthorized access.
Recommendations
For SAP Solution Manager (Diagnostics Agent) version 7.2, consider implementing additional authentication checks for the Collector Simulator functionalities to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Solution Manager