First published: Tue Jul 11 2023(Updated: )
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Solution Manager | =7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-36925.
The severity of CVE-2023-36925 is high.
The affected software is SAP Solution Manager version 7.20.
CVE-2023-36925 can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.
No, authentication is not required for exploitation of CVE-2023-36925.