CVE-2020-26821: Critical severity sap netweaver solution manager vulnerability
Published Nov 10, 2020
·Updated
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.
Affected Software
1 affected component
SAP Solution Manager=7.20
Event History
Nov 10, 2020
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-26821.
2
What is the severity of CVE-2020-26821?
The severity of CVE-2020-26821 is critical.
3
Which software versions are affected by CVE-2020-26821?
SAP Solution Manager (JAVA stack) version 7.20 is affected by CVE-2020-26821.
4
How can an attacker exploit CVE-2020-26821?
An unauthenticated attacker can compromise the system by exploiting the missing authorization checks in the SVG Converter Service of SAP Solution Manager (JAVA stack) version 7.20.
5
What is the impact of CVE-2020-26821?
CVE-2020-26821 has an impact on the integrity and availability of the service.