CVE-2020-6207
SAP Solution Manager Missing Authentication for Critical Function Vulnerability
Description
CVE-2020-6207 is a critical-severity missing authentication vulnerability in SAP Solution Manager (User Experience Monitoring). Due to a missing authentication check, the SAP Solution Manager version 7.2 does not perform any authentication for a service, resulting in complete compromise of all SMDAgents connected to the Solution Manager. This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog with confirmed active exploitation. With an EPSS score of 94.15% (99.9th percentile), CVE-2020-6207 has a near-certain probability of exploitation and represents a critical threat to SAP infrastructure.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| sap | solution manager | 7.20 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/161993/SAP-Solution-Manager-7.2-Remote-Command-Execution.html(Exploit, Third Party Advisory, VDB Entry)
- http://packetstormsecurity.com/files/162083/SAP-SMD-Agent-Unauthenticated-Remote-Code-Execution.html(Exploit, Third Party Advisory, VDB Entry)
- http://packetstormsecurity.com/files/163168/SAP-Solution-Manager-7.20-Missing-Authorization.html(Third Party Advisory)
- http://seclists.org/fulldisclosure/2021/Apr/4(Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2021/Jun/34(Mailing List, Third Party Advisory)
- https://launchpad.support.sap.com/#/notes/2890213(Permissions Required, Vendor Advisory)
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305(Broken Link, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-6207(US Government Resource)
Weakness Type
CWE-306: Missing Authentication for Critical Function
Missing Authentication for Critical Function occurs when software does not perform any authentication for functionality that requires a provable user identity. In SAP Solution Manager, the User Experience Monitoring service lacks authentication checks entirely, allowing unauthenticated attackers to interact with the service and compromise all SMDAgents connected to the Solution Manager, effectively gaining control over monitored SAP systems.
Learn more: CWE-306 — Missing Authentication for Critical Function
Impact Analysis
CVE-2020-6207 carries a CVSS 3.1 score of 9.8 (CRITICAL), indicating an extremely severe threat. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication and no user interaction, making it trivially exploitable by any attacker with network access. While the scope is unchanged, the impact is devastating: successful exploitation results in complete compromise of confidentiality, integrity, and availability across all SMDAgents connected to the Solution Manager. This means a single exploitation can cascade to compromise the entire monitored SAP landscape. The EPSS score of 94.15% (99.9th percentile) indicates near-certain exploitation activity. Organizations running SAP Solution Manager 7.2 face catastrophic risk, as the vulnerability provides a direct path to compromise multiple SAP systems through the centralized management platform.
Exploit Maturity
CVE-2020-6207 has highly mature exploitation capabilities with multiple public exploits available. Public exploit code is available via Packet Storm Security (Remote Command Execution) and Packet Storm Security (Unauthenticated Remote), providing working proof-of-concept code for remote command execution and unauthenticated remote access. CISA has confirmed active exploitation in the wild by including this vulnerability in the Known Exploited Vulnerabilities catalog. The EPSS score of 94.15% (99.9th percentile) indicates near-certain exploitation activity, placing this among the most actively targeted vulnerabilities. Full disclosure reports were published on security mailing lists, further increasing attacker awareness.
Remediation
- Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. SAP Security Note 2890213 addresses this critical missing authentication vulnerability.
- Upgrade all SAP Solution Manager 7.20 instances to the latest patched version that enforces authentication on the User Experience Monitoring service.
- If immediate patching is not possible, restrict network access to the SAP Solution Manager User Experience Monitoring service using firewall rules and network segmentation, ensuring only authorized management systems can communicate with the service.
- Audit all SMDAgents connected to the Solution Manager for signs of compromise, including unauthorized configuration changes, unexpected remote commands, and anomalous network activity originating from agent endpoints.
- Implement network monitoring for unauthenticated access attempts to the Solution Manager service, and enforce strict authentication requirements on all management and monitoring interfaces across the SAP landscape to prevent similar missing authentication issues.
Technical Details
CVE-2020-6207 is a missing authentication vulnerability in the User Experience Monitoring component of SAP Solution Manager version 7.2. The service endpoint fails to enforce any authentication check, allowing unauthenticated remote attackers to access the service and execute commands against all connected SMDAgents. The attack vector is network-based with low complexity (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), requiring no credentials and no user interaction. The unchanged scope with maximum confidentiality, integrity, and availability impact reflects that while the vulnerability itself is in the Solution Manager service, successful exploitation grants control over all connected monitoring agents, effectively providing a centralized attack path into the broader SAP infrastructure. The architecture of SAP Solution Manager as a central management hub amplifies the impact, as each connected SMDAgent represents an additional compromised endpoint.
Frequently Asked Questions
Is CVE-2020-6207 being actively exploited?
Yes. CVE-2020-6207 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Multiple public exploits are available on Packet Storm Security, and the EPSS score of 94.15% (99.9th percentile) indicates near-certain exploitation activity.
What products are affected by CVE-2020-6207?
CVE-2020-6207 affects SAP Solution Manager version 7.20, specifically the User Experience Monitoring component. All SMDAgents connected to an affected Solution Manager instance are at risk of complete compromise.
How do I fix CVE-2020-6207?
Apply updates per SAP vendor instructions, specifically SAP Security Note 2890213. Upgrade SAP Solution Manager 7.20 to the latest patched version. If immediate patching is not possible, restrict network access to the User Experience Monitoring service and audit all connected SMDAgents for signs of compromise.
How severe is CVE-2020-6207?
CVE-2020-6207 has a CVSS 3.1 score of 9.8 (CRITICAL). It allows unauthenticated remote attackers to completely compromise all SMDAgents connected to the Solution Manager without any credentials. The EPSS score of 94.15% (99.9th percentile) places this among the most critical and actively exploited SAP vulnerabilities.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.