First published: Thu Oct 15 2020(Updated: )
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Introscope Enterprise Manager | =9.7 | |
Sap Introscope Enterprise Manager | =10.1 | |
Sap Introscope Enterprise Manager | =10.5 | |
Sap Introscope Enterprise Manager | =10.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6364 is a vulnerability in SAP Solution Manager and SAP Focused Run that allows an attacker to execute OS commands and potentially gain control over the host running the CA Introscope Enterprise Manager.
CVE-2020-6364 has a severity level of critical (10).
The affected software includes SAP Introscope Enterprise Manager versions 9.7, 10.1, 10.5, and 10.7.
An attacker can exploit CVE-2020-6364 by modifying a cookie to execute malicious OS commands.
Yes, a fix has been provided in the WILY_INTRO_ENTERPRISE versions 9.7, 10.1, 10.5, and 10.7.