CVE-2020-7389

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:11.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:12.0:*:*:*:*:*:*:*

History

15 Jul 2022, 17:51

Type Values Removed Values Added
CWE CWE-306 CWE-78

04 Aug 2021, 02:05

Type Values Removed Values Added
References
  • (MISC) https://www.rapid7.com/blog/post/2021/07/07/cve-2020-7387-7390-multiple-sage-x3-vulnerabilities/ - Exploit, Third Party Advisory
References (MISC) https://rapid7.com/blog/post/2021/07/07/sage-x3-multiple-vulnerabilities-fixed - (MISC) https://rapid7.com/blog/post/2021/07/07/sage-x3-multiple-vulnerabilities-fixed - Broken Link
CPE cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:9.0:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:11.0:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:12.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 7.2
CWE CWE-306

22 Jul 2021, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-22 19:15

Updated : 2024-02-04 21:47


NVD link : CVE-2020-7389

Mitre link : CVE-2020-7389

CVE.ORG link : CVE-2020-7389


JSON object : View

Products Affected

sage

  • x3
  • syracuse
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-306

Missing Authentication for Critical Function