Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Manufacturing Execution MEDIUM 5.4
CVE-2021-27600

SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parame…

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Application Server Java MEDIUM 5.4
CVE-2021-27601

SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a…

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Application Server Java MEDIUM 5.3
CVE-2021-27598

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ…

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Master Data Management HIGH 8.3
CVE-2021-21482

SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the …

Mitigation only
Fix from $1,950 2021-04-13
Netweaver Application Server Java MEDIUM 6.5
CVE-2021-21485

An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow …

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Application Server Java MEDIUM 6.1
CVE-2021-21491

SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attack…

Mitigation only
Fix from $1,600 2021-03-10
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27585

When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer versi…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27586

When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version …

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27587

When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, t…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27588

When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27589

When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27590

When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27591

When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27592

When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes a…

Mitigation only
Fix from $1,950 2021-03-09
Payment Engine HIGH 8.8
CVE-2021-21487

SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Mitigation only
Fix from $1,950 2021-03-09
Netweaver Knowledge Management MEDIUM 6.5
CVE-2021-21488

Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w…

Mitigation only
Fix from $1,600 2021-03-09
Hana CRITICAL 9.8
CVE-2021-21484

LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi…

Mitigation only
Fix from $2,300 2021-03-09
Manufacturing Integration And Intelligence HIGH 8.8
CVE-2021-21480EPSS 51%

SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a r…

No fix yet
Fix from $1,950 2021-03-09
Netweaver HIGH 8.8
CVE-2021-21481

The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This…

Mitigation only
Fix from $1,950 2021-03-09
Enterprise Financial Services HIGH 8.8
CVE-2021-21486

SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz…

Mitigation only
Fix from $1,950 2021-03-09
Commerce CRITICAL 9.9
CVE-2021-21477EPSS 30%

SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attack…

Mitigation only
Fix from $2,300 2021-02-09
Software Provisioning Manager HIGH 8.8
CVE-2021-21472

SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installati…

Mitigation only
Fix from $1,950 2021-02-09
Netweaver Master Data Management Server HIGH 7.5
CVE-2021-21475

Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation …

Mitigation only
Fix from $1,950 2021-02-09
Hana Database MEDIUM 6.5
CVE-2021-21474

SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion is…

Mitigation only
Fix from $1,600 2021-02-09
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2021-21444

SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be…

Mitigation only
Fix from $1,600 2021-02-09
Web Dynpro Abap MEDIUM 6.1
CVE-2021-21478

SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

Mitigation only
Fix from $1,600 2021-02-09
Netweaver Master Data Management HIGH 7.5
CVE-2021-21469

When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an e…

Mitigation only
Fix from $1,950 2021-01-12
Business Warehouse MEDIUM 6.5
CVE-2021-21468

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allow…

No fix yet
Fix from $1,600 2021-01-12
Business Warehouse CRITICAL 9.9
CVE-2021-21465

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker …

No fix yet
Fix from $2,300 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21453

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12