Sap Solution Manager vulnerabilities
32 known vulnerabilities affecting sap/solution_manager.
Total CVEs
32
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH9MEDIUM14LOW1
Vulnerabilities
Page 2 of 2
CVE-2023-49587P3MEDIUMCVSS 6.4v7202023-12-12
CVE-2023-49587 [MEDIUM] CWE-77 CVE-2023-49587: SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated func
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without user interaction over the network.
nvd
CVE-2022-41275P4MEDIUMCVSS 6.1v740v7502022-12-13
CVE-2022-41275 [MEDIUM] CWE-601 CVE-2022-41275: In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing attack, with little impact on confidentiality and integrity.
nvd
CVE-2022-41261P4MEDIUMCVSS 5.5v7.202022-12-12
CVE-2022-41261 [MEDIUM] CWE-284 CVE-2022-41261: SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows
SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Successful exploitation can make the attacker access files and systems for which he/she is not a
nvd
CVE-2020-6261P4MEDIUMCVSS 5.3v7.202020-07-01
CVE-2020-6261 [MEDIUM] CWE-20 CVE-2020-6261: SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection i
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.
nvd
CVE-2020-6260P4MEDIUMCVSS 5.3v7.202020-06-10
CVE-2020-6260 [MEDIUM] CWE-91 CVE-2020-6260: SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data th
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
nvd
CVE-2023-0025P4MEDIUMCVSS 5.4v7202023-02-14
CVE-2023-0025 [MEDIUM] CWE-79 CVE-2023-0025: SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a ma
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources.
nvd
CVE-2023-23855P4MEDIUMCVSS 5.4v7202023-02-14
CVE-2023-23855 [MEDIUM] CWE-601 CVE-2023-23855: SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a maliciou
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integrity and availability.
nvd
CVE-2023-0024P4MEDIUMCVSS 5.4v7202023-02-14
CVE-2023-0024 [MEDIUM] CWE-79 CVE-2023-0024: SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a ma
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources, resulting in Cross-Site Scripting vulnerability.
nvd
CVE-2018-2405P4MEDIUMCVSS 5.4v7.10v7.202018-04-10
CVE-2018-2405 [MEDIUM] CWE-79 CVE-2018-2405: SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a mal
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
nvd
CVE-2019-0291P4MEDIUMCVSS 5.5v7.22019-05-14
CVE-2019-0291 [MEDIUM] CVE-2019-0291: Under certain conditions Solution Manager, version 7.2, allows an attacker to access information whi
Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2023-23852P4MEDIUMCVSS 6.1v7202023-02-14
CVE-2023-23852 [MEDIUM] CWE-79 CVE-2023-23852: SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
nvd
CVE-2021-21483P4MEDIUMCVSS 4.9v7.202021-04-13
CVE-2021-21483 [MEDIUM] CVE-2021-21483: Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to g
Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the application.
nvd
← Previous2 / 2