Unencrypted Connection Vulnerability in SAP Solution Manager Diagnostics Agent
CVE-2020-6198
9.8CRITICAL
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 March 2020
Summary
The SAP Solution Manager Diagnostics Agent version 720 is susceptible to a vulnerability that allows unencrypted connections from unauthenticated sources. This weakness can be exploited by attackers to gain unauthorized control over all remote functions of the Agent. By leveraging this flaw, malicious users can potentially manipulate diagnostic operations without proper authentication, leading to significant security risks for organizations utilizing this SAP solution.
Affected Version(s)
SAP Solution Manager (Diagnostics Agent) < 7.2
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved