File Upload Vulnerability in SAP Solution Manager by SAP
CVE-2025-30017

4.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 April 2025

Summary

A flaw in SAP Solution Manager 7.1 allows authenticated attackers to bypass authorization checks, leading to unauthorized file uploads as templates for solution documentation. This vulnerability can be exploited to compromise the integrity and availability of the application, posing serious risks to organizational security. Proper mitigation strategies should be employed to prevent potential exploitation.

Affected Version(s)

SAP Solution Manager ST 720

SAP Solution Manager SAP_BASIS 700

SAP Solution Manager SAP_BASIS 701

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.