CRITICAL🇵🇱 Wersja polska

CVE-2022-22544

CVSS 9.1v3.1pub. 2022-02-09upd. 2024-11-21

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing segregation of duty for the SAP Solution Manager administrator. Impacts of unauthorized execution of commands can lead to sensitive information disclosure, loss of system integrity and denial of service.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Sap Solution Manager

    APP
    Sap
    7.20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2020-6207CRITICAL9.8⚠ KEVPL ✓same product

SAP Solution Manager 7.2 – brak uwierzytelnienia w module UX Monitoring

CVE-2020-26837CRITICAL9.1PL ✓same product

SAP Solution Manager 7.2 – path traversal via upload złośliwego skryptu

CVE-2020-26823CRITICAL10.0PL ✓same product

SAP Solution Manager – brak autoryzacji w usłudze Diagnostics Agent (Auth Bypass)

CVE-2020-26821CRITICAL10.0PL ✓same product

SAP Solution Manager – brak autoryzacji w SVG Converter Service (RCE/DoS)

CVE-2020-26822CRITICAL10.0PL ✓same product

SAP Solution Manager – brak autoryzacji w Outside Discovery Configuration Service