VYPR

ST-PI

by SAP

CVEs (5)

  • CVE-2023-27893HigMar 14, 2023
    risk 0.57cvss 8.8epss 0.01

    An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to…

  • CVE-2020-6262HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the…

  • CVE-2026-24322HigFeb 10, 2026
    risk 0.50cvss 7.7epss 0.00

    SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing sensitive information to be disclosed. This vulnerability has a high impact on confidentiality and does not affect integrity…

  • CVE-2019-0293MedMay 14, 2019
    risk 0.42cvss 6.5epss 0.01

    Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).

  • CVE-2026-24313MedMar 10, 2026
    risk 0.33cvss 5.0epss 0.00

    SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks for authenticated users, allowing system information to be disclosed. This vulnerability has a low impact on confidentiality and does not affect integrity or…