CVE-2020-6364: Code Injection
SAP Solution Manager and SAP Focused Run (update provided in WILYINTROENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6364?
CVE-2020-6364 is a vulnerability in SAP Solution Manager and SAP Focused Run that allows an attacker to execute OS commands and potentially gain control over the host running the CA Introscope Enterprise Manager.
What is the severity of CVE-2020-6364?
CVE-2020-6364 has a severity level of critical (10).
What software is affected by CVE-2020-6364?
The affected software includes SAP Introscope Enterprise Manager versions 9.7, 10.1, 10.5, and 10.7.
How can an attacker exploit CVE-2020-6364?
An attacker can exploit CVE-2020-6364 by modifying a cookie to execute malicious OS commands.
Is there a fix for CVE-2020-6364?
Yes, a fix has been provided in the WILY_INTRO_ENTERPRISE versions 9.7, 10.1, 10.5, and 10.7.