Home

Description

Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.

PUBLISHED Reserved 2025-03-13 | Published 2025-04-08 | Updated 2025-04-08 | Assigner sap




MEDIUM: 4.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

ST 720
affected

SAP_BASIS 700
affected

SAP_BASIS 701
affected

SAP_BASIS 702
affected

SAP_BASIS 731
affected

SAP_BASIS 740
affected

SAP_BASIS 750
affected

SAP_BASIS 751
affected

SAP_BASIS 752
affected

SAP_BASIS 753
affected

SAP_BASIS 754
affected

SAP_BASIS 755
affected

SAP_BASIS 756
affected

SAP_BASIS 757
affected

SAP_BASIS 758
affected

SAP_BASIS 914
affected

References

me.sap.com/notes/3558864

url.sap/sapsecuritypatchday

cve.org (CVE-2025-30017)

nvd.nist.gov (CVE-2025-30017)

Download JSON