CVE-2020-26837 PUBLISHED CVSS 8.5 HIGH

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially compromise availability by making certain services unavailable.

EPSS 0.56% · 68.0th percentile

Risk Scores

CVSS v3.0
8.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
EPSS Score
0.56%
68.0th percentile

Affected Products

VendorProductVersions
SAP SESAP Solution Manager (User Experience Monitoring)< 7.20
sapsolution_manager7.20

Timeline

References

Open in Interactive Console →