Vulnerabilities > SAP > Solution Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-01 CVE-2020-6261 Improper Encoding or Escaping of Output vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation.
network
low complexity
sap CWE-116
5.3
2020-06-10 CVE-2020-6260 XML Injection (aka Blind XPath Injection) vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation.
network
low complexity
sap CWE-91
5.3
2019-05-14 CVE-2019-0291 Unspecified vulnerability in SAP Solution Manager 7.2
Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.
local
low complexity
sap
5.5
2018-04-10 CVE-2018-2405 Cross-site Scripting vulnerability in SAP Solution Manager 7.10/7.20
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
network
low complexity
sap CWE-79
5.4