SAP SE / Solution Manager
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-49587 | Command Injection vulnerability in SAP Solution Manager | MEDIUM | 6.4 | Dec 12, 2023 |
| CVE-2023-36925 | Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent) | HIGH | 7.2 | Jul 11, 2023 |
| CVE-2023-36921 | Header Injection in SAP Solution Manager (Diagnostic Agent) | HIGH | 7.2 | Jul 11, 2023 |
| CVE-2023-27893 | Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI) | HIGH | 8.8 | Mar 14, 2023 |
| CVE-2023-23855 | SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful att… | MEDIUM | 6.5 | Feb 14, 2023 |
| CVE-2023-23852 | SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabil… | MEDIUM | 6.1 | Feb 14, 2023 |
| CVE-2023-0025 | SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, c… | MEDIUM | 6.5 | Feb 14, 2023 |
| CVE-2023-0024 | SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, c… | MEDIUM | 6.5 | Feb 14, 2023 |
| CVE-2022-41275 | In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can… | MEDIUM | 6.1 | Dec 13, 2022 |
| CVE-2022-41261 | SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can… | MEDIUM | 6.0 | Dec 12, 2022 |
| CVE-2022-22544 | Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse… | CRITICAL | 9.1 | Feb 9, 2022 |
| CVE-2021-21483 | Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serio… | MEDIUM | 4.9 | Apr 13, 2021 |
| CVE-2020-26836 | SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attack… | MEDIUM | 6.1 | Dec 9, 2020 |
| CVE-2020-26837 | SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing pa… | CRITICAL | 9.1 | Dec 9, 2020 |
| CVE-2020-26830 | SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequ… | HIGH | 8.1 | Dec 9, 2020 |
| CVE-2020-26823 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the U… | CRITICAL | 10.0 | Nov 10, 2020 |
| CVE-2020-26821 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the S… | CRITICAL | 10.0 | Nov 10, 2020 |
| CVE-2020-26824 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the U… | CRITICAL | 10.0 | Nov 10, 2020 |
| CVE-2020-26822 | SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the O… | CRITICAL | 10.0 | Nov 10, 2020 |
| CVE-2020-6369 | SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the au… | MEDIUM | 5.9 | Oct 20, 2020 |
| CVE-2020-6261 | SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The r… | MEDIUM | 5.3 | Jul 1, 2020 |
| CVE-2020-6260 | SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete X… | MEDIUM | 5.3 | Jun 10, 2020 |
| CVE-2020-6271 | SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of me… | HIGH | 8.2 | Jun 10, 2020 |
| CVE-2020-6235 | SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to… | HIGH | 8.6 | Apr 14, 2020 |
| CVE-2020-6207 KEV | SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resultin… | CRITICAL | 9.8 | Mar 10, 2020 |
Showing 1 to 25 of 33 CVEs