CVE-2020-25563
PoC —CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description
In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature and not having a JSESSIONID.
- Vendors
- sapphireims
- Products
- sapphireims
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.