{"api_version":"1","generated_at":"2026-07-24T22:56:17+00:00","cve":"CVE-2013-7363","urls":{"html":"https://cve.report/CVE-2013-7363","api":"https://cve.report/api/cve/CVE-2013-7363.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-7363","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-7363"},"summary":{"title":"CVE-2013-7363","description":"Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via vectors involving the P4 protocol.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-04-10 20:55:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://archives.neohapsis.com/archives/bugtraq/2013-02/0134.html","name":"http://archives.neohapsis.com/archives/bugtraq/2013-02/0134.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://service.sap.com/sap/support/notes/1774568","name":"https://service.sap.com/sap/support/notes/1774568","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.onapsis.com/get.php?resid=adv_onapsis-2013-006","name":"http://www.onapsis.com/get.php?resid=adv_onapsis-2013-006","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Onapsis - Register","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.onapsis.com/research-advisories.php","name":"http://www.onapsis.com/research-advisories.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Page Not Found | Onapsis","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://scn.sap.com/docs/DOC-8218","name":"http://scn.sap.com/docs/DOC-8218","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Acknowledgments to Security Researchers | SCN","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-7363","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7363","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"7363","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"solution_manager","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:01:20.632Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://service.sap.com/sap/support/notes/1774568"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.onapsis.com/get.php?resid=adv_onapsis-2013-006"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://scn.sap.com/docs/DOC-8218"},{"name":"20130222 [Onapsis Security Advisory 2013-006] SAP SMD Agent Code Injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-02/0134.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.onapsis.com/research-advisories.php"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via vectors involving the P4 protocol."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-04-10T15:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://service.sap.com/sap/support/notes/1774568"},{"tags":["x_refsource_MISC"],"url":"http://www.onapsis.com/get.php?resid=adv_onapsis-2013-006"},{"tags":["x_refsource_CONFIRM"],"url":"http://scn.sap.com/docs/DOC-8218"},{"name":"20130222 [Onapsis Security Advisory 2013-006] SAP SMD Agent Code Injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-02/0134.html"},{"tags":["x_refsource_MISC"],"url":"http://www.onapsis.com/research-advisories.php"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2013-7363","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via vectors involving the P4 protocol."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://service.sap.com/sap/support/notes/1774568","refsource":"MISC","url":"https://service.sap.com/sap/support/notes/1774568"},{"name":"http://www.onapsis.com/get.php?resid=adv_onapsis-2013-006","refsource":"MISC","url":"http://www.onapsis.com/get.php?resid=adv_onapsis-2013-006"},{"name":"http://scn.sap.com/docs/DOC-8218","refsource":"CONFIRM","url":"http://scn.sap.com/docs/DOC-8218"},{"name":"20130222 [Onapsis Security Advisory 2013-006] SAP SMD Agent Code Injection","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2013-02/0134.html"},{"name":"http://www.onapsis.com/research-advisories.php","refsource":"MISC","url":"http://www.onapsis.com/research-advisories.php"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2013-7363","datePublished":"2014-04-10T15:00:00.000Z","dateReserved":"2014-04-10T00:00:00.000Z","dateUpdated":"2024-09-17T00:46:41.729Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-04-10 20:55:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sap:solution_manager:-:*:*:*:*:*:*:*","matchCriteriaId":"720D82FC-A0C1-4B34-BE92-56439FF0FDC6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"7363","Ordinal":"1","Title":"CVE-2013-7363","CVE":"CVE-2013-7363","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"7363","Ordinal":"1","NoteData":"Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the configuration of applications, and install or remove applications via vectors involving the P4 protocol.","Type":"Description","Title":"CVE-2013-7363"},{"CveYear":"2013","CveId":"7363","Ordinal":"2","NoteData":"2014-04-10","Type":"Other","Title":"Published"}]}}}