VDB
CVE-2026-0500
CVE-2026-0500
PUBLISHED
CVSS 9.600000381469727 CRITICAL
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.
EPSS 0.17% · 38.5th percentile
Risk Scores
CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score
0.17%
38.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP Wily Introscope Enterprise Manager (WorkStation) | WILY_INTRO_ENTERPRISE 10.8, WILY_INTRO_ENTERPRISE 10.8 |
| sap | introscope_enterprise_manager | 10.8, 10.8, 10.8 |
Timeline
- Jan 13, 2026 EPSS Score
- Jan 13, 2026 CVE Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 13, 2026 PoC Published
- Jan 14, 2026 PoC Published
- Jan 16, 2026 EPSS Score
- Jan 19, 2026 EPSS Score
- Jan 22, 2026 EPSS Score
- Jan 25, 2026 EPSS Score