SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations which should be restricted to administrators. These operations can be used to Change the User Experience Monitoring configuration, obtain details about the configured SAP Solution Manager agents, Deploy a malicious User Experience Monitoring script.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2020-12-09T16:29:34

Updated: 2024-08-04T16:03:22.653Z

Reserved: 2020-10-07T00:00:00

Link: CVE-2020-26830

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-09T17:15:31.133

Modified: 2021-06-17T17:19:14.553

Link: CVE-2020-26830

cve-icon Redhat

No data.