VYPR

Adxadmin

by Sage

CVEs (2)

  • CVE-2020-7388CriJul 22, 2021
    risk 0.74cvss 10.0epss 0.69

    Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can…

  • CVE-2020-7387MedJul 22, 2021
    risk 0.40cvss 5.3epss 0.36

    Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. Note that this vulnerability can be combined with CVE-2020-7388 to achieve full RCE. This issue was…