Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Marketing Sapscore MEDIUM 5.4
CVE-2018-2486

SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripti…

No fix yet
Fix from $1,600 2018-12-11
Netweaver HIGH 8.8
CVE-2018-2477

Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an …

Mitigation only
Fix from $1,950 2018-11-13
Disclosure Management HIGH 8.3
CVE-2018-2487

SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use c…

Mitigation only
Fix from $1,950 2018-11-13
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2018-2473

SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows a…

Mitigation only
Fix from $1,600 2018-11-13
Netweaver MEDIUM 6.1
CVE-2018-2476

Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.

Mitigation only
Fix from $1,600 2018-11-13
Businessobjects Bi Platform MEDIUM 6.1
CVE-2018-2479

SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resultin…

Mitigation only
Fix from $1,600 2018-11-13
Fiori MEDIUM 6.5
CVE-2018-2474

SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended req…

Mitigation only
Fix from $1,600 2018-10-09
Adaptive Server Enterprise HIGH 7.5
CVE-2018-2468

Under certain conditions the backup server in SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information …

Mitigation only
Fix from $1,950 2018-10-09
Adaptive Server Enterprise HIGH 7.5
CVE-2018-2469

Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise…

Mitigation only
Fix from $1,950 2018-10-09
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2018-2471

Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherw…

No fix yet
Fix from $1,950 2018-10-09
Businessobjects Bi Platform MEDIUM 6.1
CVE-2018-2472

SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs,…

Mitigation only
Fix from $1,600 2018-10-09
Businessobjects Bi Platform MEDIUM 5.3
CVE-2018-2467

In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser su…

Mitigation only
Fix from $1,600 2018-10-09
Data Services MEDIUM 5.4
CVE-2018-2466

In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate user-controlled inputs, which…

Mitigation only
Fix from $1,600 2018-10-09
Hana HIGH 7.5
CVE-2018-2465

SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauth…

Mitigation only
Fix from $1,950 2018-09-11
Netweaver MEDIUM 6.1
CVE-2018-2464

SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scri…

Mitigation only
Fix from $1,600 2018-09-11
People Profile HIGH 8.8
CVE-2018-2461

Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of p…

Mitigation only
Fix from $1,950 2018-09-11
Netweaver HIGH 8.8
CVE-2018-2462

In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML doc…

Mitigation only
Fix from $1,950 2018-09-11
Business One HIGH 7.5
CVE-2018-2458

Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which…

No fix yet
Fix from $1,950 2018-09-11
Mobile Platform HIGH 7.5
CVE-2018-2459

Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occ…

Mitigation only
Fix from $1,950 2018-09-11
Adaptive Server Enterprise MEDIUM 6.5
CVE-2018-2457

Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access information which would otherwise be re…

No fix yet
Fix from $1,600 2018-09-11
Business One MEDIUM 5.9
CVE-2018-2460

SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM att…

Mitigation only
Fix from $1,600 2018-09-11
Enterprise Financial Services HIGH 8.8
CVE-2018-2454

SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary aut…

Mitigation only
Fix from $1,950 2018-09-11
Enterprise Financial Services HIGH 8.8
CVE-2018-2455

SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary …

Mitigation only
Fix from $1,950 2018-09-11
Netweaver Application Server Java MEDIUM 6.1
CVE-2018-2452

The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, result…

Mitigation only
Fix from $1,600 2018-09-11
Supplier Relationship Management Mdm Catalog HIGH 8.6
CVE-2018-2449

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid reposito…

Mitigation only
Fix from $1,950 2018-08-14
Businessobjects Business Intelligence HIGH 7.5
CVE-2018-2446

Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name…

Mitigation only
Fix from $1,950 2018-08-14
Maxdb HIGH 7.2
CVE-2018-2450

SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore re…

Mitigation only
Fix from $1,950 2018-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2018-2447

SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposi…

Mitigation only
Fix from $1,600 2018-08-14
Supplier Relationship Management Mdm Catalog MEDIUM 5.3
CVE-2018-2448

Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user exis…

Mitigation only
Fix from $1,600 2018-08-14
Businessobjects Business Intelligence CRITICAL 9.6
CVE-2018-2445

AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft…

Mitigation only
Fix from $2,300 2018-08-14