PT-2022-2173 · Sap · Sap Solution Manager

Published

2022-02-08

·

Updated

2022-10-25

·

CVE-2022-22544

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Solution Manager version 720
Description The issue is related to insufficient access control in the SAP Solution Manager Diagnostics (Root Cause Analysis) tool, allowing a remote attacker to elevate their privileges. This can enable an administrator to execute code on all connected Diagnostics Agents and browse files on their systems, potentially leading to control of the managed systems. The impact of unauthorized command execution can result in sensitive information disclosure, loss of system integrity, and denial of service.
Recommendations For SAP Solution Manager version 720, consider restricting the privileges of the administrator role to minimize the risk of exploitation, and ensure proper segregation of duties to prevent unauthorized access to managed systems.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2022-02184
CVE-2022-22544

Affected Products

Sap Solution Manager