![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-6261
https://notcve.org/view.php?id=CVE-2020-6261
01 Jul 2020 — SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante llevar a cabo una inyección de registro en el archivo de rastreo, debido a una Comprobación XML Incompleta. La legibilidad del archivo de rastreo está afectada • https://launchpad.support.sap.com/#/notes/2915126 • CWE-20: Improper Input Validation CWE-116: Improper Encoding or Escaping of Output •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-6260
https://notcve.org/view.php?id=CVE-2020-6260
10 Jun 2020 — SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante inyectar datos superfluos que la aplicación puede mostrar, debido a una Comprobación XML Incompleta. La aplicación muestra datos adicionales que no existen realmente • https://launchpad.support.sap.com/#/notes/2915126 • CWE-91: XML Injection (aka Blind XPath Injection) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-6271
https://notcve.org/view.php?id=CVE-2020-6271
10 Jun 2020 — SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the system to crash and read restricted data (files visible for technical administration users of the diagnostics agent). SAP Solution Manager (Problem Context Manager), versión 7.2, no realiza la autenticación necesaria, lo que permite a un atacante consumir grandes cantidades de memoria, causando que el sistema se bloquee y lea datos r... • https://launchpad.support.sap.com/#/notes/2931391 • CWE-91: XML Injection (aka Blind XPath Injection) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-6235
https://notcve.org/view.php?id=CVE-2020-6235
14 Apr 2020 — SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication. SAP Solution Manager (Diagnostics Agent), versión 7.2, no lleva a cabo la comprobación de autenticación para las funcionalidades del Collector Simulator, conllevando a una Falta de Autenticación. • https://launchpad.support.sap.com/#/notes/2906994 • CWE-306: Missing Authentication for Critical Function •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-6207 – SAP Solution Manager Missing Authentication for Critical Function Vulnerability
https://notcve.org/view.php?id=CVE-2020-6207
10 Mar 2020 — SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager. SAP Solution Manager (User Experience Monitoring), versión 7.2, debido a una Falta de Comprobación de Autenticación no realiza ninguna autenticación para un servicio, resultando en un compromiso completo de todos los SMDAgents conectados al Solution Manager. A malicious unaut... • https://packetstorm.news/files/id/180811 • CWE-306: Missing Authentication for Critical Function •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2020-6198
https://notcve.org/view.php?id=CVE-2020-6198
10 Mar 2020 — SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check. SAP Solution Manager (Diagnostics Agent), versión 720, permite conexiones no cifradas de fuentes no autenticadas. Esto permite a un atacante controlar todas las funciones remotas en el Agente debido a una Falta de Comprobación de Autenticación. • https://launchpad.support.sap.com/#/notes/2845377 • CWE-306: Missing Authentication for Critical Function CWE-319: Cleartext Transmission of Sensitive Information •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-0307
https://notcve.org/view.php?id=CVE-2019-0307
12 Jun 2019 — Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges could gain access to the entire configuration, but no system sensitive information can be gained. Diagnostics Agent en Solution Manager, versión 7.2, almacena varias credenciales, como la conexión de usuario de SLD y la comunicación de u... • https://launchpad.support.sap.com/#/notes/2772266 • CWE-311: Missing Encryption of Sensitive Data •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-0293
https://notcve.org/view.php?id=CVE-2019-0293
14 May 2019 — Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740). La lectura del destino de RFC no siempre realiza la comprobación de autorización, dando como resultado una escalada de privilegios para acceder a la información en los destinos en RFC en sistemas administrados y en sistemas SAP Solution Manage... • http://www.securityfocus.com/bid/108324 • CWE-862: Missing Authorization •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-0291
https://notcve.org/view.php?id=CVE-2019-0291
14 May 2019 — Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted. Bajo ciertas condiciones, Solution Manager, versión 7.2, le permite a un atacante acceder a información que de otra manera sería restringida. • http://www.securityfocus.com/bid/108313 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-2405
https://notcve.org/view.php?id=CVE-2018-2405
10 Apr 2018 — SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting. En SAP Solution Manager, en versiones 7.10 y 7.20, Incident Management Work Center permite que un atacante suba un script malicioso como adjunto, lo que podría conducir a un posible Cross-Site Scripting (XSS). • http://www.securityfocus.com/bid/103703 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •