PT-2020-6763 · Sap · Sap Solution Manager

Published

2020-03-10

·

Updated

2021-07-21

·

CVE-2020-6198

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP Solution Manager (Diagnostics Agent) version 720
Description The issue is related to the transmission of data in an open format, allowing an attacker to gain unauthorized access to protected information. This is due to a missing authentication check, which enables an attacker to control all remote functions on the Diagnostics Agent.
Recommendations For SAP Solution Manager (Diagnostics Agent) version 720, consider implementing authentication checks to ensure that only authorized sources can establish connections. As a temporary workaround, restrict access to the Diagnostics Agent to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Missing Authentication

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06123
CVE-2020-6198

Affected Products

Sap Solution Manager