ZeroHour

CVE-2020-26821

CVSS 3.1
10.0 critical
EPSS
1%p70
Published
()
Modified
Description

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.

Vendors
sap
Products
solution manager
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.