CVE-2022-41261
- EPSS 0.04%
- Published 12.12.2022 22:15:10
- Last modified 21.11.2024 07:22:56
SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system f...
CVE-2022-22544
- EPSS 0.43%
- Published 09.02.2022 23:15:18
- Last modified 21.11.2024 06:46:59
Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is consid...
CVE-2021-21483
- EPSS 0.24%
- Published 13.04.2021 19:15:13
- Last modified 21.11.2024 05:48:27
Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the app...
CVE-2020-26837
- EPSS 0.56%
- Published 09.12.2020 17:15:31
- Last modified 21.11.2024 05:20:22
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file syst...
CVE-2020-26836
- EPSS 0.42%
- Published 09.12.2020 17:15:31
- Last modified 21.11.2024 05:20:22
SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or do...
CVE-2020-26830
- EPSS 0.25%
- Published 09.12.2020 17:15:31
- Last modified 21.11.2024 05:20:21
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations w...
- EPSS 0.81%
- Published 10.11.2020 17:15:14
- Last modified 21.11.2024 05:20:21
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availability of the se...
- EPSS 0.37%
- Published 10.11.2020 17:15:14
- Last modified 21.11.2024 05:20:20
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impact to the integrity and availa...
- EPSS 0.81%
- Published 10.11.2020 17:15:14
- Last modified 21.11.2024 05:20:20
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availabilit...
- EPSS 0.81%
- Published 10.11.2020 17:15:14
- Last modified 21.11.2024 05:20:20
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.