Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-7388 Details

Description

Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can be learned by exploiting CVE-2020-7387. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 including Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sage X3 HR & Payroll Version 9 (those components that ship with Syracuse 9.24.1.3), Version 11 (components shipped with Syracuse 11.25.2.6 and later), and Version 12 (components shipped with Syracuse 12.10.2.8 and later) of Sage X3. Other on-premises versions of Sage X3 are unsupported by the vendor.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-290Authentication Bypass by Spoofing[email protected]
CWE-290Authentication Bypass by Spoofing[email protected]

Affected Products

ProductVersions
sage adxadmin
< 93.2.53

CPE

  • cpe:2.3:a:sage:adxadmin:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
sage x3
9.0
11.0
12.0

CPE

  • cpe:2.3:a:sage:x3:9.0:*:*:*:*:*:*:*
  • cpe:2.3:a:sage:x3:11.0:*:*:*:*:*:*:*
  • cpe:2.3:a:sage:x3:12.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
sage x3 hr & payroll
9.0

CPE

  • cpe:2.3:a:sage:x3_hr_&_payroll:9.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-7388
NVD Published Date:
Jul 22, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2020-7388 Details - Not Deferred