Solution Manager
33 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Solution Manager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Solution Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 33 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical8
- High10
- Medium14
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Solution Manager.
- CVE-2023-49587Command Injection vulnerability in SAP Solution Manager6.4
- CVE-2023-36925Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)7.2
- CVE-2023-36921Header Injection in SAP Solution Manager (Diagnostic Agent)7.2
- CVE-2023-27893Arbitrary Code Execution in SAP Solution Manager and ABAP managed systems (ST-PI)8.8
- CVE-2023-23855SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or ...6.5
- CVE-2023-23852SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. 6.1
- CVE-2023-0025SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sens...6.5
- CVE-2023-0024SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sens...6.5
- CVE-2022-41275In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page th...6.1
- CVE-2022-41261SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration fil...6.0
- CVE-2022-22544Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker co...9.1
- CVE-2021-21483Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable compo...4.9
- CVE-2020-26836SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site ...6.1
- CVE-2020-26837SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromi...9.1
- CVE-2020-26830SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker...8.1
Product grouping is registry-driven, with AI assist and human review. How it works