Description
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations which should be restricted to administrators. These operations can be used to Change the User Experience Monitoring configuration, obtain details about the configured SAP Solution Manager agents, Deploy a malicious User Experience Monitoring script.
Published: 2020-12-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-19366 SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations which should be restricted to administrators. These operations can be used to Change the User Experience Monitoring configuration, obtain details about the configured SAP Solution Manager agents, Deploy a malicious User Experience Monitoring script.
History

No history.

Subscriptions

Sap Solution Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-04T16:03:22.653Z

Reserved: 2020-10-07T00:00:00.000Z

Link: CVE-2020-26830

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-09T17:15:31.133

Modified: 2024-11-21T05:20:21.637

Link: CVE-2020-26830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses