Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver CRITICAL 9.1
CVE-2020-6203

SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validat…

Mitigation only
Fix from $2,300 2020-03-10
Crystal Reports HIGH 8.2
CVE-2020-6208

SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code…

Mitigation only
Fix from $1,950 2020-03-10
Disclosure Management HIGH 7.5
CVE-2020-6209

SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration…

Mitigation only
Fix from $1,950 2020-03-10
Netweaver Application Server Java HIGH 7.2
CVE-2020-6202

SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate th…

Mitigation only
Fix from $1,950 2020-03-10
Commerce Cloud MEDIUM 6.1
CVE-2020-6201

The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain…

Mitigation only
Fix from $1,600 2020-03-10
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6205

SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53…

Mitigation only
Fix from $1,600 2020-03-10
Erp MEDIUM 5.4
CVE-2020-6199

The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate…

Mitigation only
Fix from $1,600 2020-03-10
Commerce Cloud MEDIUM 5.4
CVE-2020-6200

The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross…

Mitigation only
Fix from $1,600 2020-03-10
Solution Manager CRITICAL 9.8
CVE-2020-6198

SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to contro…

Mitigation only
Fix from $2,300 2020-03-10
Businessobjects Mobile HIGH 7.5
CVE-2020-6196

SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which he can block all the threads…

Mitigation only
Fix from $1,950 2020-03-10
Erp HIGH 8.8
CVE-2020-6188

VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (…

Mitigation only
Fix from $1,950 2020-02-12
Host Agent HIGH 7.5
CVE-2020-6186

SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host…

Mitigation only
Fix from $1,950 2020-02-12
Landscape Management HIGH 7.2
CVE-2020-6191

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Age…

Mitigation only
Fix from $1,950 2020-02-12
Landscape Management HIGH 7.2
CVE-2020-6192

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent …

Mitigation only
Fix from $1,950 2020-02-12
Netweaver Knowledge Management MEDIUM 6.1
CVE-2020-6193

SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts le…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver Application Server Java MEDIUM 5.8
CVE-2020-6190

Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about th…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver MEDIUM 5.4
CVE-2020-6185

Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, …

Mitigation only
Fix from $1,600 2020-02-12
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6189

Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise…

Mitigation only
Fix from $1,600 2020-02-12
Host Agent MEDIUM 6.5
CVE-2020-6183

SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPO…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver MEDIUM 6.1
CVE-2020-6184

Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53,…

Mitigation only
Fix from $1,600 2020-02-12
Abap Platform MEDIUM 5.8
CVE-2020-6181

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS ver…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver CRITICAL 9.8
CVE-2011-1517

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafte…

Mitigation only
Fix from $2,300 2020-02-05
Netweaver HIGH 7.5
CVE-2013-1593

A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 S…

No fix yet
Fix from $1,950 2020-01-23
Netweaver CRITICAL 9.8
CVE-2013-1592EPSS 24%

A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Serv…

No fix yet
Fix from $2,300 2020-01-23
Netweaver Internet Communication Manager \(kernel\) HIGH 7.5
CVE-2020-6304

Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL6…

Mitigation only
Fix from $1,950 2020-01-14
Process Integration MEDIUM 6.1
CVE-2020-6305

PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, result…

Mitigation only
Fix from $1,600 2020-01-14
Enterprise Extension Financial Services HIGH 8.8
CVE-2019-0383

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…

Mitigation only
Fix from $1,950 2019-12-17
Enterprise Extension Financial Services HIGH 8.8
CVE-2019-0384

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…

Mitigation only
Fix from $1,950 2019-12-17
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2019-0398

Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, m…

Mitigation only
Fix from $1,950 2019-12-11
Portfolio And Project Management MEDIUM 6.5
CVE-2019-0399

SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user …

Mitigation only
Fix from $1,600 2019-12-11