Path Traversal Vulnerability in SAP Solution Manager 7.2
CVE-2020-26837

8.5HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 December 2020

Summary

The vulnerability in SAP Solution Manager 7.2 allows authenticated users to upload malicious scripts, thereby exploiting an existing path traversal issue. This can result in unauthorized access to sensitive elements of the file system, compromising confidentiality. Additionally, modifications to certain configurations can occur, partially compromising the integrity of the system. Services can also be disrupted, leading to potential availability issues.

Affected Version(s)

SAP Solution Manager (User Experience Monitoring) < 7.20

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.