CVE-2020-6207

CVE Published 2020-03-10
Related CWE(s) CWE-306: Missing Authentication for Critical Function
Related Vendor(s) sap
Related Product(s) solution_manager
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 10.0 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References