CVE-2023-36925: Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)
Published Jul 11, 2023
·Updated
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.
Affected Software
1 affected component
SAP Solution Manager=7.20
Event History
Jul 11, 2023
CVE Published
via MITRE·02:57 AM
Data Sourced
via MITRE·02:57 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2023-36925.
2
What is the severity of CVE-2023-36925?
The severity of CVE-2023-36925 is high.
3
What is the affected software?
The affected software is SAP Solution Manager version 7.20.
4
How does CVE-2023-36925 impact the application?
CVE-2023-36925 can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.
5
Is authentication required for exploitation?
No, authentication is not required for exploitation of CVE-2023-36925.