5.9

CVE-2020-6369

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of the service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Focused Run Version 9.7
SAP ≫ Focused Run Version 10.1
SAP ≫ Focused Run Version 10.5
SAP ≫ Focused Run Version 10.7
SAP ≫ Solution Manager Version 9.7
SAP ≫ Solution Manager Version 10.1
SAP ≫ Solution Manager Version 10.5
SAP ≫ Solution Manager Version 10.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.67% 0.843
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
SAP 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
Vendor Advisory
http://packetstormsecurity.com/files/163159/SAP-Wily-Introscope-Enterprise-Default-Hard-Coded-Credentials.html
Third Party Advisory
http://seclists.org/fulldisclosure/2021/Jun/31
Third Party Advisory
Mailing List
https://launchpad.support.sap.com/#/notes/2971638
Vendor Advisory
Permissions Required