Vulnerability Intelligence Report
CVE-2020-26837
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially compromise availability by making certain services unavailable.
No Active Exploit Signals
CVSS Base Score
8.5
HIGH
Exploitability:3.2
Impact Score:4.8
EPSS Probability:1.87%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP SE | SAP Solution Manager (User Experience Monitoring) | < 7.20 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.872%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2020-10-07T00:00:00 |
| Published | 2020-12-09T16:31:24 |
| Last Updated | 2024-08-04T16:03:22 |
Community Chatter & Buzz