cbcvebase.

Sap Se Sap Solution Manager vulnerabilities

25 known vulnerabilities affecting sap_se/sap_solution_manager.

Total CVEs
25
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH6MEDIUM8LOW1

Vulnerabilities

Page 2 of 2
CVE-2020-6207CRITICALCVSS 9.8KEVPoCfixed in 7.22020-03-10
CVE-2020-6207 [CRITICAL] CWE-306 CVE-2020-6207: SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
nvd
CVE-2019-0307LOWCVSS 2.4PoCfixed in 7.22019-06-12
CVE-2019-0307 [LOW] CWE-311 CVE-2019-0307: Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user conn Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges could gain access to the entire configuration, but no system sensitive informatio
nvd
CVE-2019-0291MEDIUMCVSS 5.5fixed in 7.22019-05-14
CVE-2019-0291 [MEDIUM] CVE-2019-0291: Under certain conditions Solution Manager, version 7.2, allows an attacker to access information whi Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.
nvd
CVE-2018-2405MEDIUMCVSS 5.4v7.10v7.202018-04-10
CVE-2018-2405 [MEDIUM] CWE-79 CVE-2018-2405: SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a mal SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
nvd
CVE-2018-2361HIGHCVSS 8.8v7.202018-01-09
CVE-2018-2361 [HIGH] CWE-863 CVE-2018-2361: In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) co In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.
nvd