The bug in HPE SIM makes it easy as pie for attackers to remotely trigger code, no user interaction necessary. The bug is an extremely high-risk flaw that can enable attackers with no privileges to remotely execute code: Tracked as CVE-2020-7200, it s rated 9.8 out of a maximum 10. The problem stems from a failure to validate data during the deserialization process when a user submits a POST request to the /simsearch/messagebroker/amfsecure page.
Source: https://threatpost.com/hpe-fixes-critical-zero-day-sim/166543/