Advisory
On 13.10.2020 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within Solution Manager.
SAP Note 2969828 addresses "[CVE-2020-6364] OS Command Injection Vulnerability in CA Introscope Enterprise Manager (Affected Products: SAP Solution Manager and SAP Focused Run)" to prevent program error with a hot news risk for exploitation.
A workaround does exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
In release 10.7.0.304 or lower an unauthenticated attacker can execute remote OS command injection within CA Interscope Enterprise Manager.Solution
The manufacturer recommends upgrading vulnerable versions of CA Interscope Enterprise Manager. According to the suggestion provided within the SAP Note, there are two update procedures, depending on the base version which is in use. Circumstances exist that prevent the timely installation of a patch provided by the manufacturer. In such cases, you may consider applying the suggested workaround as a temporary or compensating mitigation: "Stop the Interscope Enterprise Manager service until an upgrade is possible.".
The advisory is valid for
- WILY_INTRO_ENTERPRISE 9.7 2
- WILY_INTRO_ENTERPRISE 10.1 2
- WILY_INTRO_ENTERPRISE 10.5 2
- WILY_INTRO_ENTERPRISE 10.7 2