SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2020-10-15T01:55:24
Updated: 2024-08-04T09:02:40.251Z
Reserved: 2020-01-08T00:00:00
Link: CVE-2020-6364
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-10-15T02:15:12.780
Modified: 2024-11-21T05:35:35.067
Link: CVE-2020-6364
Redhat
No data.