Severity
10.0CRITICAL
EPSS
0.8%
top 25.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateMay 24

Description

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:HExploitability: 3.9 | Impact: 5.8

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-mc9w-c56j-233f: SAP Solution Manager (JAVA stack), version - 72022-05-24
CVEList
CVE-2020-26822: SAP Solution Manager (JAVA stack), version - 72020-11-10
CVE-2020-26822 (CRITICAL CVSS 10) | SAP Solution Manager (JAVA stack) | cvebase.io