Skip to main content

Vendor/product archive

sap / solution_manager CVEs

Beta · best-effort

33 CVEs tagged to sap / solution_manager8 Critical, 10 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2023-49587

Published Dec 12, 2023

SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without u…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36925

Published Jul 11, 2023

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36921

Published Jul 11, 2023

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned conte…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27893

Published Mar 14, 2023

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23855

Published Feb 14, 2023

SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an at…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23852

Published Feb 14, 2023

SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0025

Published Feb 14, 2023

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0024

Published Feb 14, 2023

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41275

Published Dec 13, 2022

In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a m…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41261

Published Dec 12, 2022

SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22544

Published Feb 9, 2022

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their syste…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21483

Published Apr 13, 2021

Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-26837

Published Dec 9, 2020

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnera…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26836

Published Dec 9, 2020

SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26830

Published Dec 9, 2020

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control,…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26824

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26823

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics A…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26822

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Con…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26821

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6369

Published Oct 20, 2020

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-6261

Published Jul 1, 2020

SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the tr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6271

Published Jun 10, 2020

SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the sy…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6260

Published Jun 10, 2020

SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6235

Published Apr 14, 2020

SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authenticat…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6207

Published Mar 10, 2020

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compro…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
65.2
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2