Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Business Planning And Consolidation MEDIUM 5.4
CVE-2020-6368

SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modif…

Mitigation only
Fix from $1,600 2020-10-15
Bank Analyzer MEDIUM 6.5
CVE-2020-6311

Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per…

Mitigation only
Fix from $1,600 2020-09-09
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6324

SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacke…

Mitigation only
Fix from $1,600 2020-09-09
Marketing HIGH 8.1
CVE-2020-6320

SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of …

Mitigation only
Fix from $1,950 2020-09-09
Abap Platform HIGH 7.2
CVE-2020-6318EPSS 6%

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi…

No fix yet
Fix from $1,950 2020-09-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2020-6321

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2020-09-09
Netweaver Knowledge Management MEDIUM 5.4
CVE-2020-6326

SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked…

Mitigation only
Fix from $1,600 2020-09-09
Commerce HIGH 8.1
CVE-2020-6302

SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacke…

Mitigation only
Fix from $1,950 2020-09-09
Netweaver Application Server Java MEDIUM 6.5
CVE-2020-6313

SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an…

Mitigation only
Fix from $1,600 2020-09-09
Fiori Launchpad MEDIUM 6.1
CVE-2020-6283

SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad ht…

Mitigation only
Fix from $1,600 2020-09-09
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2020-6312

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrati…

Mitigation only
Fix from $1,600 2020-09-09
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6288

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file…

Mitigation only
Fix from $1,600 2020-09-09
Businessobjects Business Intelligence Platform CRITICAL 9.1
CVE-2020-6294

Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun…

Mitigation only
Fix from $2,300 2020-08-12
Abap Platform HIGH 8.8
CVE-2020-6296

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject co…

Mitigation only
Fix from $1,950 2020-08-12
Generic Market Data HIGH 8.1
CVE-2020-6298

SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Marke…

Mitigation only
Fix from $1,950 2020-08-12
Hcm Travel Management HIGH 8.1
CVE-2020-6301

SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify…

No fix yet
Fix from $1,950 2020-08-12
Adaptive Server Enterprise HIGH 7.8
CVE-2020-6295

Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat…

Mitigation only
Fix from $1,950 2020-08-12
Netweaver Application Server Java HIGH 7.5
CVE-2020-6309

SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authent…

Mitigation only
Fix from $1,950 2020-08-12
Netweaver Knowledge Management CRITICAL 9.0
CVE-2020-6284

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to ina…

Mitigation only
Fix from $2,300 2020-08-12
Netweaver Knowledge Management MEDIUM 6.5
CVE-2020-6293

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to ac…

Mitigation only
Fix from $1,600 2020-08-12
Netweaver Application Server Java CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…

Mitigation only
Fix from $2,300 2020-07-14
Disclosure Management HIGH 8.8
CVE-2020-6289

SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to brow…

Mitigation only
Fix from $1,950 2020-07-14
Disclosure Management HIGH 8.8
CVE-2020-6291

SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating o…

Mitigation only
Fix from $1,950 2020-07-14
Disclosure Management HIGH 8.8
CVE-2020-6292

Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expirati…

Mitigation only
Fix from $1,950 2020-07-14
Disclosure Management MEDIUM 6.3
CVE-2020-6290

SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session…

Mitigation only
Fix from $1,600 2020-07-14
Netweaver MEDIUM 6.5
CVE-2020-6285

SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to…

Mitigation only
Fix from $1,600 2020-07-14
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2020-6276

SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-…

Mitigation only
Fix from $1,600 2020-07-14
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2020-6281

SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting refle…

Mitigation only
Fix from $1,600 2020-07-14
Netweaver Application Server Java MEDIUM 5.8
CVE-2020-6282

SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-…

Mitigation only
Fix from $1,600 2020-07-14
Disclosure Management MEDIUM 5.4
CVE-2020-6267

Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.

Mitigation only
Fix from $1,600 2020-07-14