Junglewise Threat Intelligence

CVE-2020-6207: SAP Solution Manager Missing Authentication for Critical Function Vulnerability

CVE-2020-6207 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Vendors: SAP.

Executive brief

SAP Solution Manager 7.2 (User Experience Monitoring) fails to perform authentication for a critical service. This vulnerability allows an unauthenticated remote attacker to achieve complete compromise of all SMDAgents connected to the Solution Manager.

Affected products

  • SAP Solution Manager (User Experience Monitoring) 7.2

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-03-25: exploited: Public exploit released on Packet Storm
  • 2021-11-03: disclosed