VYPR

Solution Manager

by SAP

CVEs (42)

  • CVE-2020-6207CriKEVMar 10, 2020
    risk 0.87cvss 9.8epss 0.98

    SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

  • CVE-2020-6364CriOct 15, 2020
    risk 0.66cvss 10.0epss 0.06

    SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise…

  • CVE-2025-42880CriDec 9, 2025
    risk 0.65cvss 9.9epss 0.04

    Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality,…

  • CVE-2020-26824CriNov 10, 2020
    risk 0.65cvss 10.0epss 0.01

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availability of the service.

  • CVE-2020-26823CriNov 10, 2020
    risk 0.65cvss 10.0epss 0.01

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impact to the integrity and availability of the service.

  • CVE-2020-26822CriNov 10, 2020
    risk 0.65cvss 10.0epss 0.01

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service.

  • CVE-2020-26821CriNov 10, 2020
    risk 0.65cvss 10.0epss 0.01

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.

  • CVE-2025-42887CriNov 11, 2025
    risk 0.64cvss 9.9epss 0.01

    Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality,…

  • CVE-2020-6198CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.01

    SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check.

  • CVE-2022-22544CriFeb 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing…

  • CVE-2020-26837CriDec 9, 2020
    risk 0.59cvss 9.1epss 0.02

    SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise…

  • CVE-2023-27893HigMar 14, 2023
    risk 0.57cvss 8.8epss 0.01

    An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to…

  • CVE-2018-2361HigJan 9, 2018
    risk 0.57cvss 8.8epss 0.01

    In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.

  • CVE-2020-6235HigApr 14, 2020
    risk 0.56cvss 8.6epss 0.02

    SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication.

  • CVE-2020-26830HigDec 9, 2020
    risk 0.53cvss 8.1epss 0.01

    SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a regular user can use operations which should be restricted to…

  • CVE-2020-6271HigJun 10, 2020
    risk 0.53cvss 8.2epss 0.01

    SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the system to crash and read restricted data (files visible for technical administration users of the…

  • CVE-2025-27428HigApr 8, 2025
    risk 0.50cvss 7.7epss 0.01

    Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high…

  • CVE-2016-10005HigDec 19, 2016
    risk 0.49cvss 7.5epss 0.02

    Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.

  • CVE-2023-36925HigJul 11, 2023
    risk 0.47cvss 7.2epss 0.01

    SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the…

  • CVE-2023-36921HigJul 11, 2023
    risk 0.47cvss 7.2epss 0.01

    SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a limited impact on…

Page 1 of 3