CVE-2020-7389

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:11.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:12.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
References () https://rapid7.com/blog/post/2021/07/07/sage-x3-multiple-vulnerabilities-fixed - Broken Link () https://rapid7.com/blog/post/2021/07/07/sage-x3-multiple-vulnerabilities-fixed - Broken Link
CVSS v2 : 9.0
v3 : 7.2
v2 : 9.0
v3 : 5.5

15 Jul 2022, 17:51

Type Values Removed Values Added
CWE CWE-306 CWE-78

04 Aug 2021, 02:05

Type Values Removed Values Added
References
  • (MISC) https://www.rapid7.com/blog/post/2021/07/07/cve-2020-7387-7390-multiple-sage-x3-vulnerabilities/ - Exploit, Third Party Advisory
References (MISC) https://rapid7.com/blog/post/2021/07/07/sage-x3-multiple-vulnerabilities-fixed - (MISC) https://rapid7.com/blog/post/2021/07/07/sage-x3-multiple-vulnerabilities-fixed - Broken Link
CPE cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:9.0:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:11.0:*:*:*:*:*:*:*
cpe:2.3:a:sage:x3:12.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 7.2
CWE CWE-306

22 Jul 2021, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-22 19:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7389

Mitre link : CVE-2020-7389

CVE.ORG link : CVE-2020-7389


JSON object : View

Products Affected

sage

  • x3
  • syracuse
CWE
CWE-306

Missing Authentication for Critical Function

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')