Unencrypted Connection Vulnerability in SAP Solution Manager Diagnostics Agent
CVE-2020-6198

9.8CRITICAL

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 March 2020

Summary

The SAP Solution Manager Diagnostics Agent version 720 is susceptible to a vulnerability that allows unencrypted connections from unauthenticated sources. This weakness can be exploited by attackers to gain unauthorized control over all remote functions of the Agent. By leveraging this flaw, malicious users can potentially manipulate diagnostic operations without proper authentication, leading to significant security risks for organizations utilizing this SAP solution.

Affected Version(s)

SAP Solution Manager (Diagnostics Agent) < 7.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.