PT-2020-19066 · Sap · Sap Solution Manager

Published

2020-06-10

·

Updated

2020-06-16

·

CVE-2020-6271

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP Solution Manager (Problem Context Manager) version 7.2
Description The issue allows an attacker to consume large amounts of memory, causing the system to crash and potentially read restricted data, specifically files visible to technical administration users of the diagnostics agent, due to insufficient authentication.
Recommendations For SAP Solution Manager (Problem Context Manager) version 7.2, consider implementing additional authentication mechanisms to prevent unauthorized access and memory consumption. As a temporary workaround, restrict access to sensitive files and the diagnostics agent to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6271

Affected Products

Sap Solution Manager