CVE-2020-26824
https://notcve.org/view.php?id=CVE-2020-26824
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availability of the service. SAP Solution Manager (JAVA stack), versión - 7.20, permite a un atacante no autenticado comprometer el sistema debido a una falta de comprobación de autorización en Upgrade Legacy Ports Service, esto presenta un impacto en la integridad y disponibilidad del servicio • https://launchpad.support.sap.com/#/notes/2985866 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571 • CWE-306: Missing Authentication for Critical Function •
CVE-2020-26822
https://notcve.org/view.php?id=CVE-2020-26822
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service. SAP Solution Manager (JAVA stack), versión - 7.20, permite a un atacante no autenticado comprometer el sistema debido a una falta de comprobación de autorización en Outside Discovery Configuration Service, esto presenta un impacto en la integridad y disponibilidad del servicio • https://launchpad.support.sap.com/#/notes/2985866 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571 • CWE-306: Missing Authentication for Critical Function •
CVE-2020-6261
https://notcve.org/view.php?id=CVE-2020-6261
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante llevar a cabo una inyección de registro en el archivo de rastreo, debido a una Comprobación XML Incompleta. La legibilidad del archivo de rastreo está afectada • https://launchpad.support.sap.com/#/notes/2915126 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 • CWE-20: Improper Input Validation CWE-116: Improper Encoding or Escaping of Output •
CVE-2020-6260
https://notcve.org/view.php?id=CVE-2020-6260
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante inyectar datos superfluos que la aplicación puede mostrar, debido a una Comprobación XML Incompleta. La aplicación muestra datos adicionales que no existen realmente • https://launchpad.support.sap.com/#/notes/2915126 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 • CWE-91: XML Injection (aka Blind XPath Injection) •
CVE-2020-6207 – SAP Solution Manager Missing Authentication for Critical Function Vulnerability
https://notcve.org/view.php?id=CVE-2020-6207
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager. SAP Solution Manager (User Experience Monitoring), versión 7.2, debido a una Falta de Comprobación de Autenticación no realiza ninguna autenticación para un servicio, resultando en un compromiso completo de todos los SMDAgents conectados al Solution Manager. SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. • http://packetstormsecurity.com/files/161993/SAP-Solution-Manager-7.2-Remote-Command-Execution.html http://packetstormsecurity.com/files/162083/SAP-SMD-Agent-Unauthenticated-Remote-Code-Execution.html http://packetstormsecurity.com/files/163168/SAP-Solution-Manager-7.20-Missing-Authorization.html http://seclists.org/fulldisclosure/2021/Apr/4 http://seclists.org/fulldisclosure/2021/Jun/34 https://launchpad.support.sap.com/#/notes/2890213 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305 ht • CWE-306: Missing Authentication for Critical Function •