← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-26821

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:5.8
EPSS Probability:1.34%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
SAP SE SAP Solution Manager (JAVA stack) < 7.20 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.340%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySAP SE · Vendor · Germany
Reserved2020-10-07T00:00:00
Published2020-11-10T16:17:32
Last Updated2024-08-04T16:03:22

LINK COPIED TO CLIPBOARD