Sap Se Sap Solution Manager vulnerabilities
25 known vulnerabilities affecting sap_se/sap_solution_manager.
Total CVEs
25
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH6MEDIUM8LOW1
Vulnerabilities
Page 2 of 2
CVE-2020-6260P4MEDIUMCVSS 5.3fixed in 7.202020-06-10
CVE-2020-6260 [MEDIUM] CWE-91 CVE-2020-6260: SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data th
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
nvd
CVE-2018-2405P4MEDIUMCVSS 5.4v7.10v7.202018-04-10
CVE-2018-2405 [MEDIUM] CWE-79 CVE-2018-2405: SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a mal
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
nvd
CVE-2019-0291P4MEDIUMCVSS 5.5fixed in 7.22019-05-14
CVE-2019-0291 [MEDIUM] CVE-2019-0291: Under certain conditions Solution Manager, version 7.2, allows an attacker to access information whi
Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2021-21483P4MEDIUMCVSS 4.9fixed in 7202021-04-13
CVE-2021-21483 [MEDIUM] CVE-2021-21483: Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to g
Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the application.
nvd
CVE-2025-30017P4MEDIUMCVSS 4.4vST 720vSAP_BASIS 700+14 more2025-04-08
CVE-2025-30017 [MEDIUM] CWE-862 CVE-2025-30017: Due to a missing authorization check, an authenticated attacker could upload a file as a template fo
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.
nvd
← Previous2 / 2