CVE-2023-36925 HIGH

CVE-2023-36925: Unauthenticated blind SSRF in SAP Solution Manager (Diagnostics agent)

Vendor Sap_Se
Product SAP Solution Manager (Diagnostics agent)
Weakness CWE-918 · SSRF
Published July 11, 2023
Last update November 12, 2024

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L

What the vulnerability does

01Description

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application and other applications the Diagnostics Agent can reach.

Key dates

02Disclosure timeline

July 11, 2023 CVE published
November 12, 2024 Record updated