Vulnerability Details CVE-2019-0307
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges could gain access to the entire configuration, but no system sensitive information can be gained.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.061
EPSS Ranking 90.4%
CVSS Severity
CVSS v3 Score 2.4
CVSS v2 Score 2.7
Products affected by CVE-2019-0307
-
cpe:2.3:a:sap:solution_manager:7.2