Lucene search

K
cvelistRapid7CVELIST:CVE-2020-7389
HistoryJul 07, 2021 - 12:00 a.m.

CVE-2020-7389 Sage X3 Syracuse Missing Authentication for Critical Function in Developer Environment

2021-07-0700:00:00
CWE-306
rapid7
www.cve.org
1

5.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

7.1 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.0%

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

CNA Affected

[
  {
    "product": "X3",
    "vendor": "Sage",
    "versions": [
      {
        "lessThan": "Syracuse 9.22.7.2",
        "status": "affected",
        "version": "V9",
        "versionType": "custom"
      },
      {
        "lessThan": "Syracuse 11.25.2.6",
        "status": "affected",
        "version": "V11",
        "versionType": "custom"
      },
      {
        "lessThan": "Syracuse 12.10.2.8",
        "status": "affected",
        "version": "V12",
        "versionType": "custom"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

7.1 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.0%

Related for CVELIST:CVE-2020-7389