Sap solution manager
This hub aggregates every CVE we track for Sap solution manager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
5
Critical
3
High
1
In CISA KEV
Severity distribution
MEDIUM6CRITICAL5HIGH3LOW1
Monthly trend
0
0
0
0
0
0
1
0
0
0
0
0
0
1
1
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Sap solution manager.
- CVE-2025-42880Code Injection vulnerability in SAP Solution Manager9.9
- CVE-2025-42887Code Injection vulnerability in SAP Solution Manager9.9
- CVE-2025-30017Missing Authorization check in SAP Solution Manager4.4
- CVE-2023-49587Command Injection vulnerability in SAP Solution Manager6.4
- CVE-2023-36925Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)7.2
- CVE-2023-36921Header Injection in SAP Solution Manager (Diagnostic Agent)7.2
- CVE-2022-41261SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration fil...6.0
- CVE-2022-22544Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker co...9.1
- CVE-2021-21483Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable compo...4.9
- CVE-2020-6207SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAge...KEV9.8
- CVE-2020-6198SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missi...9.8
- CVE-2019-0307Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted...2.4
- CVE-2019-0291Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.5.5
- CVE-2018-2405SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.5.4
- CVE-2018-2361In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.8.8
Product normalization is registry-driven with AI assist and human review. How it works