Vulnerabilities > SAP > Solution Manager > 7.20

DATE CVE VULNERABILITY TITLE RISK
2020-11-10 CVE-2020-26822 Missing Authentication for Critical Function vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service.
network
low complexity
sap CWE-306
critical
10.0
2020-11-10 CVE-2020-26821 Missing Authentication for Critical Function vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.
network
low complexity
sap CWE-306
critical
10.0
2020-07-01 CVE-2020-6261 Improper Encoding or Escaping of Output vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation.
network
low complexity
sap CWE-116
5.3
2020-06-10 CVE-2020-6260 XML Injection (aka Blind XPath Injection) vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation.
network
low complexity
sap CWE-91
5.3
2020-03-10 CVE-2020-6207 Missing Authentication for Critical Function vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
network
low complexity
sap CWE-306
critical
9.8
2020-03-10 CVE-2020-6198 Cleartext Transmission of Sensitive Information vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources.
network
low complexity
sap CWE-319
critical
9.8
2018-04-10 CVE-2018-2405 Cross-site Scripting vulnerability in SAP Solution Manager 7.10/7.20
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
network
low complexity
sap CWE-79
5.4
2018-01-09 CVE-2018-2361 Incorrect Authorization vulnerability in SAP Solution Manager 7.20
In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.
network
low complexity
sap CWE-863
8.8
2016-12-19 CVE-2016-10005 Information Exposure vulnerability in SAP Solution Manager 7.1/7.20/7.31
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.
network
low complexity
sap CWE-200
7.5