CVE-2019-0307: Low severity sap netweaver solution manager vulnerability
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges could gain access to the entire configuration, but no system sensitive information can be gained.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-0307?
CVE-2019-0307 is a vulnerability in the Diagnostics Agent in Solution Manager version 7.2.
What is the severity of CVE-2019-0307?
CVE-2019-0307 has a severity rating of low (2.4).
How does CVE-2019-0307 impact SAP Solution Manager version 7.2?
CVE-2019-0307 allows an attacker with admin privileges to gain unauthorized access to credentials stored by the Diagnostics Agent in Solution Manager version 7.2.
Is the SAP Secure Storage file encrypted by default in Solution Manager version 7.2?
No, the SAP Secure Storage file in Solution Manager version 7.2 is not encrypted by default.
How can I mitigate the CVE-2019-0307 vulnerability in Solution Manager version 7.2?
To mitigate CVE-2019-0307, you can encrypt the SAP Secure Storage file in Solution Manager version 7.2.