Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-6369


SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of the service.


Published

2020-10-20T14:15:14.897

Last Modified

2024-11-21T05:35:35.603

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap focused_run 9.7 Yes
Application sap focused_run 10.1 Yes
Application sap focused_run 10.5 Yes
Application sap focused_run 10.7 Yes
Application sap solution_manager 9.7 Yes
Application sap solution_manager 10.1 Yes
Application sap solution_manager 10.5 Yes
Application sap solution_manager 10.7 Yes

References