Vulnerabilities
Vulnerable Software
Sap:  >> Solution Manager  >> 7.20  Security Vulnerabilities
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impact to the integrity and availability of the service.
CVSS Score
10.0
EPSS Score
0.004
Published
2020-11-10
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availability of the service.
CVSS Score
10.0
EPSS Score
0.008
Published
2020-11-10
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.
CVSS Score
5.3
EPSS Score
0.002
Published
2020-07-01
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.
CVSS Score
6.5
EPSS Score
0.002
Published
2020-06-10
CVE-2020-6207
Known exploited
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
CVSS Score
10.0
EPSS Score
0.943
Published
2020-03-10
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.
CVSS Score
9.8
EPSS Score
0.002
Published
2020-03-10
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-04-10
In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-01-09
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.
CVSS Score
7.5
EPSS Score
0.01
Published
2016-12-19


Contact Us

Shodan ® - All rights reserved