Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0307


Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges could gain access to the entire configuration, but no system sensitive information can be gained.


Published

2019-06-12T15:29:00.377

Last Modified

2024-11-21T04:16:39.727

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 2.4 (LOW)

CVSSv2 Vector

AV:A/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

5.1

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-311

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap solution_manager 7.2 Yes

References