CVE-2020-6207criticalunder attackCWE-306

CVE-2020-6207: critical vulnerability in SAP Solution Manager (User Experience…

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 10epss 98%
from disclosure to weapon310 days
Published on NVDMar 10
1st PoC+310d
metasploit+207d
CISA KEV+603d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

SAP Solution Manager version 7.2 has a service that doesn't require any login or authentication, allowing anyone to take complete control of all connected monitoring agents without needing credentials.

Technical detail

CWE-306 (Missing Authentication Check) in SAP Solution Manager 7.2 User Experience Monitoring allows unauthenticated access to a service, enabling attackers to compromise all SMDAgents connected to the instance. No valid credentials or prior authorization required; remote exploitation possible.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — SAP Solution Manager (User Experience…

In the same product, most dangerous first.