Record summary

CVE-2020-26836 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as a parameter in the application URL and share it with the end user who could potentially become a victim of the attack.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 14, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

SAP Solution Manager (Trace Analysis)

Browse SAP SE / SAP Solution Manager (Trace Analysis)
CVE List< 720affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSAP Solution Manager - Open RedirectCVSS 6.1

SAP Solution Manager contains an open redirect vulnerability via the logoff endpoint. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Attackers can redirect users to malicious websites through crafted links, potentially facilitating phishing attacks or credential theft.

Remediation

Apply security patches or updates provided by SAP to fix the vulnerability.

WeaknessesCWE-601
AuthorsGal Nagli, LRVT
Template tagscvecve2020redirectsapvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:sap:solution_manager:7.20:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5