Vulnerability record · CVE-2020-6207 · published 10 March 2020
CVE-2020-6207: SAP Solution Manager User Experience Monitoring missing authentication
Sap · Solution Manager
SAP Solution Manager 7.2 User Experience Monitoring fails to perform any authentication for a service, matching CWE-306 (missing authentication for critical function). Because the service is reachable without credentials, an unauthenticated attacker can fully compromise all SMDAgents connected to the Solution Manager.
Description
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing, near-maximum EPSS probability and public exploit code make this an urgent, actively targeted flaw.
What it is
SAP Solution Manager 7.2 User Experience Monitoring fails to perform any authentication for a service, matching CWE-306 (missing authentication for critical function). Because the service is reachable without credentials, an unauthenticated attacker can fully compromise all SMDAgents connected to the Solution Manager.
Impact
An attacker gains complete control over every connected SMDAgent, which can lead to remote code execution on those agents. This is a full loss of confidentiality, integrity and availability across the affected Solution Manager and its managed agents.
Attack surface
The flaw is network-reachable (CVSS AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any host that can reach the exposed service can attempt it. No authentication is required by design of the vulnerable service.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS shows a 30-day exploitation probability of 0.98266 (99.9th percentile). Multiple references are tagged Exploit, indicating public exploit code exists.
What to do
- Apply the SAP vendor updates referenced in SAP Note 2890213 as soon as possible.
- Restrict network access to the Solution Manager User Experience Monitoring service and SMDAgent communication ports to trusted hosts only.
- Isolate Solution Manager and its SMDAgents from untrusted networks and monitor for unauthorized connections.
- Verify all connected SMDAgents are patched and re-check for signs of compromise after remediation.
- If patching cannot be done immediately, disable or block the affected service until the update is applied.
Detection
- Monitor network traffic to the Solution Manager User Experience Monitoring service for unauthenticated or anomalous requests.
- Review Solution Manager and SMDAgent logs for unexpected service calls, new connections, or command execution events.
- Hunt for known exploit artifacts or payloads associated with the public exploit references for this CVE.
- Alert on any SMDAgent behavior indicating remote code execution or unexpected configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-6207 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP Solution Manager Missing Authentication for Critical Function Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-6207 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-6207), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.