Sage X3 Syracuse Missing Authentication for Critical Function in Developer Environment
CVE-2020-7389

5.5MEDIUM

Key Information:

Vendor

Sage

Status
Vendor
CVE Published:
22 July 2021

What is CVE-2020-7389?

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

Affected Version(s)

X3 V9

X3 V11

X3 V12

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonathan Peterson, Aaron Herndon, Cale Black, Ryan Villarrea, and William Vu, all of Rapid7
.