- Description
- Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could execute OS commands on the victim's machine. This could completely compromising confidentiality, integrity and availability of the system.
- Source
- cna@sap.com
- NVD status
- Analyzed
- Products
- introscope_enterprise_manager
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- cna@sap.com
- CWE-94
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:introscope_enterprise_manager:10.8:*:*:*:*:*:*:*",
"matchCriteriaId": "EB7AE9DD-2761-40DE-8E74-09AB4F93A8D6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]