CVE-2020-6261
https://notcve.org/view.php?id=CVE-2020-6261
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante llevar a cabo una inyección de registro en el archivo de rastreo, debido a una Comprobación XML Incompleta. La legibilidad del archivo de rastreo está afectada • https://launchpad.support.sap.com/#/notes/2915126 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 • CWE-20: Improper Input Validation CWE-116: Improper Encoding or Escaping of Output •
CVE-2020-6260
https://notcve.org/view.php?id=CVE-2020-6260
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist. SAP Solution Manager (Trace Analysis), versión 7.20, permite a un atacante inyectar datos superfluos que la aplicación puede mostrar, debido a una Comprobación XML Incompleta. La aplicación muestra datos adicionales que no existen realmente • https://launchpad.support.sap.com/#/notes/2915126 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 • CWE-91: XML Injection (aka Blind XPath Injection) •
CVE-2020-6271
https://notcve.org/view.php?id=CVE-2020-6271
SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amounts of memory, causing the system to crash and read restricted data (files visible for technical administration users of the diagnostics agent). SAP Solution Manager (Problem Context Manager), versión 7.2, no realiza la autenticación necesaria, lo que permite a un atacante consumir grandes cantidades de memoria, causando que el sistema se bloquee y lea datos restringidos (archivos visibles para usuarios de administración técnica del agente de diagnóstico) • https://launchpad.support.sap.com/#/notes/2931391 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 • CWE-91: XML Injection (aka Blind XPath Injection) •
CVE-2020-6235
https://notcve.org/view.php?id=CVE-2020-6235
SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication. SAP Solution Manager (Diagnostics Agent), versión 7.2, no lleva a cabo la comprobación de autenticación para las funcionalidades del Collector Simulator, conllevando a una Falta de Autenticación. • https://launchpad.support.sap.com/#/notes/2906994 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202 • CWE-306: Missing Authentication for Critical Function •
CVE-2020-6207 – SAP Solution Manager Missing Authentication for Critical Function Vulnerability
https://notcve.org/view.php?id=CVE-2020-6207
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager. SAP Solution Manager (User Experience Monitoring), versión 7.2, debido a una Falta de Comprobación de Autenticación no realiza ninguna autenticación para un servicio, resultando en un compromiso completo de todos los SMDAgents conectados al Solution Manager. SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. • http://packetstormsecurity.com/files/161993/SAP-Solution-Manager-7.2-Remote-Command-Execution.html http://packetstormsecurity.com/files/162083/SAP-SMD-Agent-Unauthenticated-Remote-Code-Execution.html http://packetstormsecurity.com/files/163168/SAP-Solution-Manager-7.20-Missing-Authorization.html http://seclists.org/fulldisclosure/2021/Apr/4 http://seclists.org/fulldisclosure/2021/Jun/34 https://launchpad.support.sap.com/#/notes/2890213 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305 ht • CWE-306: Missing Authentication for Critical Function •