Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Businessobjects Business Intelligence Platform HIGH 7.1
CVE-2019-0396

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently valida…

Mitigation only
Fix from $1,950 2019-11-13
Erp Sales MEDIUM 6.3
CVE-2019-0386

Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1…

Mitigation only
Fix from $1,600 2019-11-13
Ui MEDIUM 5.3
CVE-2019-0388

SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content d…

Mitigation only
Fix from $1,600 2019-11-13
Netweaver Application Server Java HIGH 8.8
CVE-2019-0389

An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privile…

Mitigation only
Fix from $1,950 2019-11-13
Hana Database HIGH 7.5
CVE-2019-0350

SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP…

Mitigation only
Fix from $1,950 2019-11-04
Financial Consolidation MEDIUM 6.5
CVE-2019-0370

Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere wi…

Mitigation only
Fix from $1,600 2019-10-08
Dynamic Tier MEDIUM 5.5
CVE-2019-0381

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can resul…

Mitigation only
Fix from $1,600 2019-10-08
Financial Consolidation MEDIUM 5.4
CVE-2019-0369

SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute …

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0374

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0375

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0376

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0377

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controll…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0378

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlle…

Mitigation only
Fix from $1,600 2019-10-08
Process Integration MEDIUM 5.3
CVE-2019-0379

SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security pro…

Mitigation only
Fix from $1,600 2019-10-08
Customer Relationship Management Bbpcrm MEDIUM 5.4
CVE-2019-0368

SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does…

Mitigation only
Fix from $1,600 2019-10-08
Sap Kernel HIGH 7.5
CVE-2019-0365

SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22…

Mitigation only
Fix from $1,950 2019-09-10
Hana MEDIUM 6.7
CVE-2019-0357

The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.

Mitigation only
Fix from $1,600 2019-09-10
Supplier Relationship Management MEDIUM 6.1
CVE-2019-0361

SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode us…

Mitigation only
Fix from $1,600 2019-09-10
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2019-0352

In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an…

Mitigation only
Fix from $1,950 2019-09-10
Netweaver Application Server Java HIGH 7.2
CVE-2019-0355

SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6…

Mitigation only
Fix from $1,950 2019-09-10
Advanced Business Application Programming Platform Kernel HIGH 7.2
CVE-2019-0349

SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.…

Mitigation only
Fix from $1,950 2019-08-14
Commerce Cloud CRITICAL 9.8
CVE-2019-0344 KEVEPSS 7%

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex…

Mitigation only
Fix from $2,300 2019-08-14
Netweaver Application Server Java CRITICAL 9.8
CVE-2019-0345

A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30…

Mitigation only
Fix from $2,300 2019-08-14
Enable Now HIGH 8.8
CVE-2019-0341

The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the a…

Mitigation only
Fix from $1,950 2019-08-14
Commerce Cloud HIGH 8.8
CVE-2019-0343

SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject …

Mitigation only
Fix from $1,950 2019-08-14
Netweaver HIGH 8.8
CVE-2019-0351

A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Becau…

Mitigation only
Fix from $1,950 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0346

Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0348

SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if th…

Mitigation only
Fix from $1,600 2019-08-14
Netweaver Process Integration MEDIUM 6.1
CVE-2019-0337

Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled in…

Mitigation only
Fix from $1,600 2019-08-14
Gateway MEDIUM 5.3
CVE-2019-0338

During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set,…

Mitigation only
Fix from $1,600 2019-08-14