CVE-2020-6364
Estado: ModificadaCrítica (10)—
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.41%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
- http://packetstormsecurity.com/files/163153/SAP-Wily-Introscope-Enterprise-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2021/Jun/28
- https://launchpad.support.sap.com/#/notes/2969828
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
- http://packetstormsecurity.com/files/163153/SAP-Wily-Introscope-Enterprise-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2021/Jun/28
- https://launchpad.support.sap.com/#/notes/2969828
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-6364",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "cna@sap.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP SE",
"product": "SAP Solution Manager (CA Introscope Enterprise Manager) and SAP Focused Run (CA Introscope Enterprise Manager)",
"versions": [
{
"status": "affected",
"version": "< WILY_INTRO_ENTERPRISE 9.7"
},
{
"status": "affected",
"version": "< 10.1"
},
{
"status": "affected",
"version": "< 10.5"
},
{
"status": "affected",
"version": "< 10.7"
}
]
}
]
}
],
"published": "2020-10-15T02:15:12.780",
"references": [
{
"url": "http://packetstormsecurity.com/files/163153/SAP-Wily-Introscope-Enterprise-OS-Command-Injection.html",
"tags": [
"Third Party Advisory"
],
"source": "cna@sap.com"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Jun/28",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2969828",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "http://packetstormsecurity.com/files/163153/SAP-Wily-Introscope-Enterprise-OS-Command-Injection.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2021/Jun/28",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2969828",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code Injection. With this, the attacker is able to read and modify all system files and also impact system availability."
},
{
"lang": "es",
"value": "SAP Solution Manager y SAP Focused Run (actualización proporcionada en WILY_INTRO_ENTERPRISE versiones 9.7, 10.1, 10.5, 10.7), permite a un atacante modificar una cookie de manera que los comandos del Sistema Operativo puedan ser ejecutados y potencialmente conseguir el control sobre el host que ejecuta CA Introscope Enterprise Manager, conllevando a una inyección de código. Con esto, el atacante es capaz de leer y modificar todos los archivos del sistema y también afectar la disponibilidad del sistema"
}
],
"lastModified": "2026-06-17T03:23:11.453",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:introscope_enterprise_manager:9.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "280649F4-6210-48BB-9C51-FA58A24B068F"
},
{
"criteria": "cpe:2.3:a:sap:introscope_enterprise_manager:10.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F623A68-CBF7-4CFA-9489-85F8636299A1"
},
{
"criteria": "cpe:2.3:a:sap:introscope_enterprise_manager:10.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE1FEE0B-A8C2-4D87-A4A4-7CE4A5FF10F0"
},
{
"criteria": "cpe:2.3:a:sap:introscope_enterprise_manager:10.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "05898DD8-CCD0-4E06-A49B-0891782865D4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}