PT-2020-19066 · Sap · Sap Solution Manager
Published
2020-06-10
·
Updated
2020-06-16
·
CVE-2020-6271
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Solution Manager (Problem Context Manager) version 7.2
Description
The issue allows an attacker to consume large amounts of memory, causing the system to crash and potentially read restricted data, specifically files visible to technical administration users of the diagnostics agent, due to insufficient authentication.
Recommendations
For SAP Solution Manager (Problem Context Manager) version 7.2, consider implementing additional authentication mechanisms to prevent unauthorized access and memory consumption. As a temporary workaround, restrict access to sensitive files and the diagnostics agent to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Solution Manager