Vulnerabilities > SAP > Solution Manager > 7.20
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-11-10 | CVE-2020-26822 | Missing Authentication for Critical Function vulnerability in SAP Solution Manager 7.20 SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service. | 10.0 |
2020-11-10 | CVE-2020-26821 | Missing Authentication for Critical Function vulnerability in SAP Solution Manager 7.20 SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service. | 10.0 |
2020-07-01 | CVE-2020-6261 | Improper Encoding or Escaping of Output vulnerability in SAP Solution Manager 7.20 SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. | 5.3 |
2020-06-10 | CVE-2020-6260 | XML Injection (aka Blind XPath Injection) vulnerability in SAP Solution Manager 7.20 SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. | 5.3 |
2020-03-10 | CVE-2020-6207 | Missing Authentication for Critical Function vulnerability in SAP Solution Manager 7.20 SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager. | 9.8 |
2020-03-10 | CVE-2020-6198 | Cleartext Transmission of Sensitive Information vulnerability in SAP Solution Manager 7.20 SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. | 9.8 |
2018-04-10 | CVE-2018-2405 | Cross-site Scripting vulnerability in SAP Solution Manager 7.10/7.20 SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting. | 5.4 |
2018-01-09 | CVE-2018-2361 | Incorrect Authorization vulnerability in SAP Solution Manager 7.20 In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools. | 8.8 |
2016-12-19 | CVE-2016-10005 | Information Exposure vulnerability in SAP Solution Manager 7.1/7.20/7.31 Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524. | 7.5 |