Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Fiori Launchpad \(news Tile Application\) MEDIUM 6.1
CVE-2020-26825

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile…

Mitigation only
Fix from $1,600 2020-11-13
Solution Manager CRITICAL 10.0
CVE-2020-26821

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26822

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26823

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26824

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Netweaver Application Server Abap HIGH 8.8
CVE-2020-26819

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone…

Mitigation only
Fix from $1,950 2020-11-10
Netweaver Application Server Java HIGH 7.2
CVE-2020-26820

SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator …

No fix yet
Fix from $1,950 2020-11-10
Netweaver Application Server Abap HIGH 8.8
CVE-2020-26818

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone…

Mitigation only
Fix from $1,950 2020-11-10
Fiori Launchpad \(news Tile Application\) HIGH 8.6
CVE-2020-26815

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulne…

Mitigation only
Fix from $1,950 2020-11-10
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-26817

SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing …

Mitigation only
Fix from $1,950 2020-11-10
Commerce Cloud \(accelerator Payment Mock\) HIGH 7.5
CVE-2020-26810

SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…

Mitigation only
Fix from $1,950 2020-11-10
Sap As Abap\(dmis\) HIGH 7.2
CVE-2020-26808

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), version…

No fix yet
Fix from $1,950 2020-11-10
Commerce Cloud MEDIUM 5.3
CVE-2020-26809

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpo…

No fix yet
Fix from $1,600 2020-11-10
Commerce Cloud \(accelerator Payment Mock\) MEDIUM 5.3
CVE-2020-26811

SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…

No fix yet
Fix from $1,600 2020-11-10
Banking Services MEDIUM 6.5
CVE-2020-6362

SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with othe…

Mitigation only
Fix from $1,600 2020-10-20
Netweaver Compare Systems MEDIUM 6.5
CVE-2020-6366

SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administra…

Mitigation only
Fix from $1,600 2020-10-20
Netweaver Composite Application Framework MEDIUM 6.1
CVE-2020-6367

There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An…

Mitigation only
Fix from $1,600 2020-10-20
Focused Run MEDIUM 5.9
CVE-2020-6369

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to byp…

No fix yet
Fix from $1,600 2020-10-20
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6315

SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive…

Mitigation only
Fix from $1,600 2020-10-20
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6308EPSS 62%

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary va…

Mitigation only
Fix from $1,600 2020-10-20
Netweaver Application Server Java MEDIUM 6.1
CVE-2020-6365

SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to…

Mitigation only
Fix from $1,600 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6372

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6373

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6374

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which …

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6375

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted …

Mitigation only
Fix from $1,600 2020-10-15
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6376

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources wh…

Mitigation only
Fix from $1,600 2020-10-15
Introscope Enterprise Manager CRITICAL 10.0
CVE-2020-6364EPSS 6%

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a…

Mitigation only
Fix from $2,300 2020-10-15
Netweaver Application Server Java MEDIUM 6.1
CVE-2020-6319

SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScri…

Mitigation only
Fix from $1,600 2020-10-15
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2020-6323

SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an…

Mitigation only
Fix from $1,600 2020-10-15
Commerce Cloud MEDIUM 5.4
CVE-2020-6272

SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content …

Mitigation only
Fix from $1,600 2020-10-15