Описание
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162083/SAP-SMD-Agent-Unauthenticated-Remote-Code-Execution.htmlExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Permissions RequiredVendor Advisory
- Broken LinkVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162083/SAP-SMD-Agent-Unauthenticated-Remote-Code-Execution.htmlExploitThird Party AdvisoryVDB Entry
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Permissions RequiredVendor Advisory
- Broken LinkVendor Advisory
- US Government Resource
Уязвимые конфигурации
EPSS
10 Critical
CVSS3
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
Связанные уязвимости
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
Уязвимость компонента User Experience Monitoring платформы управления программными средами SAP Solution Manager, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
EPSS
10 Critical
CVSS3
9.8 Critical
CVSS3
10 Critical
CVSS2