CVE-2020-25563: Sapphireims

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTaskSave (Automation Tasks) feature and not having a JSESSIONID.

Affected products

Published 2021-08-11. Last modified 2026-06-17.