Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0333

In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the at…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2019-0332

SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the se…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2019-0335

Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker …

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 5.4
CVE-2019-0334

When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malici…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 5.3
CVE-2019-0331

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, allows an attacker to access sen…

Mitigation only
Fix from $1,600 2019-08-14
Diagnostics Agent CRITICAL 9.1
CVE-2019-0330

The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to …

Mitigation only
Fix from $2,300 2019-07-10
Netweaver Application Server Java HIGH 7.2
CVE-2019-0327

SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.…

Mitigation only
Fix from $1,950 2019-07-10
Netweaver Process Integration HIGH 7.2
CVE-2019-0328

ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS c…

Mitigation only
Fix from $1,950 2019-07-10
Information Steward MEDIUM 6.1
CVE-2019-0329

SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Mitigation only
Fix from $1,600 2019-07-10
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2019-0326

SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not sufficiently encode user-controlled …

Mitigation only
Fix from $1,600 2019-07-10
Gateway HIGH 7.5
CVE-2019-0319

The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attac…

No fix yet
Fix from $1,950 2019-07-10
Commerce Cloud HIGH 7.5
CVE-2019-0322

SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent l…

Mitigation only
Fix from $1,950 2019-07-10
Netweaver Application Server Abap MEDIUM 6.1
CVE-2019-0321

ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip…

Mitigation only
Fix from $1,600 2019-07-10
Netweaver Application Server Java MEDIUM 5.3
CVE-2019-0318

Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker…

Mitigation only
Fix from $1,600 2019-07-10
Businessobjects MEDIUM 6.1
CVE-2019-0303

SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested…

Mitigation only
Fix from $1,600 2019-06-14
Netweaver Process Integration HIGH 7.5
CVE-2019-0315

Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31,…

Mitigation only
Fix from $1,950 2019-06-12
R\/3 Enterprise MEDIUM 6.1
CVE-2019-0311

Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-contr…

Mitigation only
Fix from $1,600 2019-06-12
Work Manager MEDIUM 5.5
CVE-2019-0314

SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a ser…

Mitigation only
Fix from $1,600 2019-06-12
Netweaver Process Integration MEDIUM 5.3
CVE-2019-0312

Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to…

Mitigation only
Fix from $1,600 2019-06-12
Advanced Business Application Programming Platform Kernel CRITICAL 9.8
CVE-2019-0304

FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.…

Mitigation only
Fix from $2,300 2019-06-12
E Commerce MEDIUM 6.8
CVE-2019-0308

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the pro…

Mitigation only
Fix from $1,600 2019-06-12
Identity Management HIGH 8.8
CVE-2019-0301

Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface …

Mitigation only
Fix from $1,950 2019-05-14
Treasury And Risk Management HIGH 8.8
CVE-2019-0280

SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform nec…

Mitigation only
Fix from $1,950 2019-05-14
Businessobjects HIGH 7.6
CVE-2019-0287

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to …

No fix yet
Fix from $1,950 2019-05-14
Businessobjects HIGH 7.1
CVE-2019-0289

Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access i…

Mitigation only
Fix from $1,950 2019-05-14
Sap Solution Manager System MEDIUM 6.5
CVE-2019-0293

Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC de…

Mitigation only
Fix from $1,600 2019-05-14
E Commerce MEDIUM 6.1
CVE-2019-0298

SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulner…

Mitigation only
Fix from $1,600 2019-05-14
Solution Manager MEDIUM 5.5
CVE-2019-0291

Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.

No fix yet
Fix from $1,600 2019-05-14
Crystal Reports CRITICAL 9.8
CVE-2019-0285EPSS 7%

The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including crede…

No fix yet
Fix from $2,300 2019-04-10
Netweaver Process Integration HIGH 7.1
CVE-2019-0283

SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofi…

Mitigation only
Fix from $1,950 2019-04-10