Vulnerabilities > SAP > Solution Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-12 CVE-2023-49587 Command Injection vulnerability in SAP Solution Manager 720
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without user interaction over the network.
network
low complexity
sap CWE-77
6.4
2023-02-14 CVE-2023-0024 Cross-site Scripting vulnerability in SAP Solution Manager 720
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources, resulting in Cross-Site Scripting vulnerability.
network
low complexity
sap CWE-79
5.4
2023-02-14 CVE-2023-0025 Cross-site Scripting vulnerability in SAP Solution Manager 720
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources.
network
low complexity
sap CWE-79
5.4
2023-02-14 CVE-2023-23852 Cross-site Scripting vulnerability in SAP Solution Manager 720
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2023-02-14 CVE-2023-23855 Open Redirect vulnerability in SAP Solution Manager 720
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation.
network
low complexity
sap CWE-601
5.4
2022-12-13 CVE-2022-41275 Open Redirect vulnerability in SAP Solution Manager 740/750
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing attack, with little impact on confidentiality and integrity.
network
low complexity
sap CWE-601
6.1
2022-12-12 CVE-2022-41261 Unspecified vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files.
local
low complexity
sap
5.5
2021-04-13 CVE-2021-21483 Unspecified vulnerability in SAP Solution Manager 7.20
Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the application.
network
low complexity
sap
4.9
2020-12-09 CVE-2020-26836 Open Redirect vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as a parameter in the application URL and share it with the end user who could potentially become a victim of the attack.
network
low complexity
sap CWE-601
6.1
2020-10-20 CVE-2020-6369 Unspecified vulnerability in SAP Focused RUN and Solution Manager
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of the service.
network
high complexity
sap
5.9