Page 3 of 35 results (0.006 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

01 Jul 2020 — SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante llevar a cabo una inyección de registro en el archivo de rastreo, debido a una Comprobación XML Incompleta. La legibilidad del archivo de rastreo está afectada • https://launchpad.support.sap.com/#/notes/2915126 • CWE-20: Improper Input Validation CWE-116: Improper Encoding or Escaping of Output •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

10 Jun 2020 — SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante inyectar datos superfluos que la aplicación puede mostrar, debido a una Comprobación XML Incompleta. La aplicación muestra datos adicionales que no existen realmente • https://launchpad.support.sap.com/#/notes/2915126 • CWE-91: XML Injection (aka Blind XPath Injection) •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

10 Jun 2020 — SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the system to crash and read restricted data (files visible for technical administration users of the diagnostics agent). SAP Solution Manager (Problem Context Manager), versión 7.2, no realiza la autenticación necesaria, lo que permite a un atacante consumir grandes cantidades de memoria, causando que el sistema se bloquee y lea datos r... • https://launchpad.support.sap.com/#/notes/2931391 • CWE-91: XML Injection (aka Blind XPath Injection) •

CVSS: 8.6EPSS: 0%CPEs: 1EXPL: 0

14 Apr 2020 — SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication. SAP Solution Manager (Diagnostics Agent), versión 7.2, no lleva a cabo la comprobación de autenticación para las funcionalidades del Collector Simulator, conllevando a una Falta de Autenticación. • https://launchpad.support.sap.com/#/notes/2906994 • CWE-306: Missing Authentication for Critical Function •

CVSS: 10.0EPSS: 97%CPEs: 1EXPL: 5

10 Mar 2020 — SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager. SAP Solution Manager (User Experience Monitoring), versión 7.2, debido a una Falta de Comprobación de Autenticación no realiza ninguna autenticación para un servicio, resultando en un compromiso completo de todos los SMDAgents conectados al Solution Manager. A malicious unaut... • https://packetstorm.news/files/id/180811 • CWE-306: Missing Authentication for Critical Function •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

10 Mar 2020 — SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication Check. SAP Solution Manager (Diagnostics Agent), versión 720, permite conexiones no cifradas de fuentes no autenticadas. Esto permite a un atacante controlar todas las funciones remotas en el Agente debido a una Falta de Comprobación de Autenticación. • https://launchpad.support.sap.com/#/notes/2845377 • CWE-306: Missing Authentication for Critical Function CWE-319: Cleartext Transmission of Sensitive Information •

CVSS: 2.7EPSS: 0%CPEs: 1EXPL: 0

12 Jun 2019 — Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges could gain access to the entire configuration, but no system sensitive information can be gained. Diagnostics Agent en Solution Manager, versión 7.2, almacena varias credenciales, como la conexión de usuario de SLD y la comunicación de u... • https://launchpad.support.sap.com/#/notes/2772266 • CWE-311: Missing Encryption of Sensitive Data •

CVSS: 6.5EPSS: 0%CPEs: 3EXPL: 0

14 May 2019 — Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740). La lectura del destino de RFC no siempre realiza la comprobación de autorización, dando como resultado una escalada de privilegios para acceder a la información en los destinos en RFC en sistemas administrados y en sistemas SAP Solution Manage... • http://www.securityfocus.com/bid/108324 • CWE-862: Missing Authorization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

14 May 2019 — Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted. Bajo ciertas condiciones, Solution Manager, versión 7.2, le permite a un atacante acceder a información que de otra manera sería restringida. • http://www.securityfocus.com/bid/108313 •

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

10 Apr 2018 — SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting. En SAP Solution Manager, en versiones 7.10 y 7.20, Incident Management Work Center permite que un atacante suba un script malicioso como adjunto, lo que podría conducir a un posible Cross-Site Scripting (XSS). • http://www.securityfocus.com/bid/103703 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •