High severity7.5NVD Advisory· Published Dec 19, 2016· Updated May 6, 2026
CVE-2016-10005
CVE-2016-10005
Description
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.
Affected products
9cpe:2.3:a:sap:solution_manager:7.1:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:sap:solution_manager:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.1:sp10:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.1:sp12:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.1:sp14:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.1:sp5:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.20:*:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.20:sp01:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.20:sp03:*:*:*:*:*:*
- cpe:2.3:a:sap:solution_manager:7.31:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- packetstormsecurity.com/files/140232/SAP-Solman-7.31-Information-Disclosure.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/92949nvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2016/Dec/69nvd
- erpscan.io/advisories/erpscan-16-035-sap-solman-user-accounts-dislosure/nvd
News mentions
0No linked articles in our index yet.