CVE-2025-30017
- EPSS 0.02%
- Published 08.04.2025 07:15:02
- Last modified 08.04.2025 18:13:53
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availab...
CVE-2023-49587
- EPSS 0.11%
- Published 12.12.2023 02:15:08
- Last modified 21.11.2024 08:33:36
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without user interaction over the network.
CVE-2023-36925
- EPSS 0.5%
- Published 11.07.2023 03:15:10
- Last modified 21.11.2024 08:10:56
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application a...
CVE-2023-36921
- EPSS 0.31%
- Published 11.07.2023 03:15:10
- Last modified 21.11.2024 08:10:55
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a ...
CVE-2023-27893
- EPSS 3.39%
- Published 14.03.2023 06:15:12
- Last modified 21.11.2024 07:53:38
An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute ...
CVE-2023-0025
- EPSS 0.18%
- Published 14.02.2023 04:15:11
- Last modified 21.11.2024 07:36:25
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restri...
CVE-2023-23852
- EPSS 0.47%
- Published 14.02.2023 04:15:11
- Last modified 21.11.2024 07:46:57
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2023-23855
- EPSS 0.06%
- Published 14.02.2023 04:15:11
- Last modified 21.11.2024 07:46:58
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishi...
CVE-2023-0024
- EPSS 0.25%
- Published 14.02.2023 04:15:10
- Last modified 21.11.2024 07:36:25
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restri...
CVE-2022-41275
- EPSS 1.28%
- Published 13.12.2022 04:15:25
- Last modified 21.11.2024 07:22:57
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expos...