cbcvebase.

Sap Se Sap Solution Manager vulnerabilities

25 known vulnerabilities affecting sap_se/sap_solution_manager.

Total CVEs
25
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH6MEDIUM8LOW1

Vulnerabilities

Page 1 of 2
CVE-2025-42880CRITICALCVSS 9.9vST 7202025-12-09
CVE-2025-42880 [CRITICAL] CWE-94 CVE-2025-42880: Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert mal Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.
nvd
CVE-2025-42887CRITICALCVSS 9.9vST 7202025-11-11
CVE-2025-42887 [CRITICAL] CWE-94 CVE-2025-42887: Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert mal Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.
nvd
CVE-2025-30017MEDIUMCVSS 4.4vST 720vSAP_BASIS 700+14 more2025-04-08
CVE-2025-30017 [MEDIUM] CWE-862 CVE-2025-30017: Due to a missing authorization check, an authenticated attacker could upload a file as a template fo Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.
nvd
CVE-2023-49587MEDIUMCVSS 6.4v7202023-12-12
CVE-2023-49587 [MEDIUM] CWE-77 CVE-2023-49587: SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated func SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without user interaction over the network.
nvd
CVE-2023-36925HIGHCVSS 7.2v7.202023-07-11
CVE-2023-36925 [HIGH] CWE-918 CVE-2023-36925: SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blind SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.
nvd
CVE-2023-36921HIGHCVSS 7.2v7.202023-07-11
CVE-2023-36921 [HIGH] CWE-644 CVE-2023-36921: SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers i SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application.
nvd
CVE-2022-22544CRITICALCVSS 9.1v7202022-02-09
CVE-2022-22544 [CRITICAL] CVE-2022-22544: Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to e Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing segregation of duty for the SAP Solution Manager administrator. Impacts of unau
nvd
CVE-2021-21483MEDIUMCVSS 4.9fixed in 7202021-04-13
CVE-2021-21483 [MEDIUM] CVE-2021-21483: Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to g Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the application.
nvd
CVE-2020-26837CRITICALCVSS 9.1fixed in 7.202020-12-09
CVE-2020-26837 [CRITICAL] CWE-22 CVE-2020-26837: SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user t SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially co
nvd
CVE-2020-26830HIGHCVSS 8.1fixed in 7.202020-12-09
CVE-2020-26830 [HIGH] CWE-862 CVE-2020-26830: SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary aut SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations which should be restricted to administrators. These operations can be used to Change the User Experience
nvd
CVE-2020-26836MEDIUMCVSS 6.1PoCfixed in 7202020-12-09
CVE-2020-26836 [MEDIUM] CWE-601 CVE-2020-26836: SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the applic SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as a parameter in the application URL and share it with the end user who c
nvd
CVE-2020-26823CRITICALCVSS 10.0fixed in 7.202020-11-10
CVE-2020-26823 [CRITICAL] CWE-306 CVE-2020-26823: SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impact to the integrity and availability of the service.
nvd
CVE-2020-26824CRITICALCVSS 10.0fixed in 7.202020-11-10
CVE-2020-26824 [CRITICAL] CWE-306 CVE-2020-26824: SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availability of the service.
nvd
CVE-2020-26822CRITICALCVSS 10.0fixed in 7.202020-11-10
CVE-2020-26822 [CRITICAL] CWE-306 CVE-2020-26822: SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service.
nvd
CVE-2020-26821CRITICALCVSS 10.0fixed in 7.202020-11-10
CVE-2020-26821 [CRITICAL] CWE-306 CVE-2020-26821: SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.
nvd
CVE-2020-6261MEDIUMCVSS 5.3fixed in 7.202020-07-01
CVE-2020-6261 [MEDIUM] CWE-20 CVE-2020-6261: SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection i SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.
nvd
CVE-2020-6271HIGHCVSS 8.2fixed in 7.22020-06-10
CVE-2020-6271 [HIGH] CWE-91 CVE-2020-6271: SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authenti SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the system to crash and read restricted data (files visible for technical administration users of the diagnostics agent).
nvd
CVE-2020-6260MEDIUMCVSS 5.3fixed in 7.202020-06-10
CVE-2020-6260 [MEDIUM] CWE-91 CVE-2020-6260: SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data th SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
nvd
CVE-2020-6235HIGHCVSS 8.6fixed in 7.22020-04-14
CVE-2020-6235 [HIGH] CWE-306 CVE-2020-6235: SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication.
nvd
CVE-2020-6198CRITICALCVSS 9.8fixed in 7.22020-03-10
CVE-2020-6198 [CRITICAL] CWE-306 CVE-2020-6198: SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthent SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.
nvd