CVE-2025-42880
- EPSS 0.05%
- Veröffentlicht 09.12.2025 02:15:09
- Zuletzt bearbeitet 09.12.2025 18:36:53
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impac...
CVE-2025-42887
- EPSS 0.06%
- Veröffentlicht 11.11.2025 00:14:45
- Zuletzt bearbeitet 12.11.2025 16:19:59
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impac...
CVE-2025-30017
- EPSS 0.02%
- Veröffentlicht 08.04.2025 07:15:02
- Zuletzt bearbeitet 08.04.2025 18:13:53
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availab...
CVE-2023-49587
- EPSS 0.11%
- Veröffentlicht 12.12.2023 02:15:08
- Zuletzt bearbeitet 21.11.2024 08:33:36
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which can read or modify data of same or other component without user interaction over the network.
CVE-2023-36925
- EPSS 0.5%
- Veröffentlicht 11.07.2023 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:56
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application a...
CVE-2023-36921
- EPSS 0.31%
- Veröffentlicht 11.07.2023 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:55
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a ...
CVE-2023-27893
- EPSS 4.45%
- Veröffentlicht 14.03.2023 06:15:12
- Zuletzt bearbeitet 21.11.2024 07:53:38
An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute ...
CVE-2023-23852
- EPSS 0.59%
- Veröffentlicht 14.02.2023 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:46:57
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2023-0025
- EPSS 0.23%
- Veröffentlicht 14.02.2023 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:36:25
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restri...
CVE-2023-23855
- EPSS 0.08%
- Veröffentlicht 14.02.2023 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:46:58
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishi...