Description
SAP Solution Manager is a product developed by the software company SAP SE.
SAP Solution Manager (User Experience Monitoring), version 7.2, does not perform any authentication for a service (due to a Missing Authentication Check) resulting in complete compromise of all SMDAgents connected to the Solution Manager.
Remediation
Upgrade to the latest version of SAP Solution Manager.
References
Related Vulnerabilities
Django Resource Management Errors Vulnerability (CVE-2011-4137)
WordPress Plugin WooCommerce Cross-Site Scripting (2.6.8)
SharePoint Improper Input Validation Vulnerability (CVE-2019-1257)
WordPress Plugin Video Conferencing with Zoom Cross-Site Scripting (4.0.9)
WebLogic Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2020-7226)