CVE-2020-6207: critical vulnerability in SAP Solution Manager (User Experience…
Published · Updated
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 10epss 98%
from disclosure to weapon310 days
Published on NVDMar 10
1st PoC+310d
metasploit+207d
CISA KEV+603d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
5 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03
Apply updates per vendor instructions.
In short
SAP Solution Manager version 7.2 has a service that doesn't require any login or authentication, allowing anyone to take complete control of all connected monitoring agents without needing credentials.
Technical detail
CWE-306 (Missing Authentication Check) in SAP Solution Manager 7.2 User Experience Monitoring allows unauthenticated access to a service, enabling attackers to compromise all SMDAgents connected to the instance. No valid credentials or prior authorization required; remote exploitation possible.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
SAP SE · SAP Solution Manager (User Experience Monitoring)public PoCs found — 5
githubgithub.com/chipik/SAP_EEM_CVE-2020-6207★ 82cve_referencepacketstormsecurity.com/files/161993/SAP-Solution-Manager-7.2-Remote-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/162083/SAP-SMD-Agent-Unauthenticated-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/163168/SAP-Solution-Manager-7.20-Missing-Authorization.htmlunverifiedvulncheckvulncheck.com/xdb/453413941eabunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — SAP Solution Manager (User Experience…
In the same product, most dangerous first.
References
http://packetstormsecurity.com/files/161993/SAP-Solution-Manager-7.2-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/162083/SAP-SMD-Agent-Unauthenticated-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/163168/SAP-Solution-Manager-7.20-Missing-Authorization.htmlhttp://seclists.org/fulldisclosure/2021/Apr/4http://seclists.org/fulldisclosure/2021/Jun/34https://launchpad.support.sap.com/#/notes/2890213https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6207