Showing 4 vulnerabilities on this page for Solution Manager

Signals CISA KEV Ransomware Nuclei
SAP vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integrity and availability.

CWE-601Feb 14, 2023
CVSS6.5v3.1EPSS0.302%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CWE-79Feb 14, 2023
CVSS6.1v3.1EPSS0.418%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SAP Solution Manager URL Redirection to Untrusted Site ('Open Redirect')

SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as a parameter in the application URL and share it with the end user who could potentially become a victim of the attack.

CWE-601Dec 9, 20201 related artifact
CVSS6.1v3.1EPSS2.34%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SAP Solution Manager Missing Authentication for Critical Function Vulnerability

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.

CWE-306Mar 10, 20201 related artifact
CVSS9.8v3.1EPSS98.3%PoCs2SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX