First published: Tue Jul 11 2023(Updated: )
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Solution Manager | =7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-36921.
CVE-2023-36921 has a severity level of high (7).
SAP Solution Manager version 7.20 is affected by CVE-2023-36921.
CVE-2023-36921 can cause a limited impact on confidentiality and availability.
Yes, you can refer to the following links for more information: [Link 1](https://me.sap.com/notes/3348145), [Link 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).