Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Businessobjects Business Intelligence HIGH 8.8
CVE-2018-2442

In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session …

Mitigation only
Fix from $1,950 2018-08-14
Businessobjects Financial Consolidation MEDIUM 6.1
CVE-2018-2444

SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script…

Mitigation only
Fix from $1,600 2018-08-14
Sap Kernel MEDIUM 5.5
CVE-2018-2441

Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unico…

No fix yet
Fix from $1,600 2018-08-14
Business Planning And Consolidation HIGH 8.1
CVE-2017-16349

An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e…

Mitigation only
Fix from $1,950 2018-08-02
Internet Graphics Server CRITICAL 9.1
CVE-2018-2437

The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can l…

Mitigation only
Fix from $2,300 2018-07-10
R\/3 Enterprise Retail HIGH 8.8
CVE-2018-2436

Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting i…

Mitigation only
Fix from $1,950 2018-07-10
Internet Graphics Server HIGH 7.5
CVE-2018-2438

The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prev…

Mitigation only
Fix from $1,950 2018-07-10
Internet Graphics Server MEDIUM 5.9
CVE-2018-2439

The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is valid…

Mitigation only
Fix from $1,600 2018-07-10
Sap Kernel HIGH 7.5
CVE-2018-2433

SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.2…

Mitigation only
Fix from $1,950 2018-07-10
Hana Database HIGH 7.5
CVE-2018-2424

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to th…

Mitigation only
Fix from $1,950 2018-06-12
Business One MEDIUM 5.5
CVE-2018-2425

Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be r…

Mitigation only
Fix from $1,600 2018-06-12
Infrastructure MEDIUM 5.3
CVE-2018-2428

Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected a…

Mitigation only
Fix from $1,600 2018-06-12
Internet Transaction Server MEDIUM 6.1
CVE-2018-11415EPSS 8%

SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indic…

No fix yet
Fix from $1,600 2018-05-24
Internet Graphics Server HIGH 7.5
CVE-2018-2422

SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…

Mitigation only
Fix from $1,950 2018-05-09
Internet Graphics Server HIGH 7.5
CVE-2018-2423

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from access…

Mitigation only
Fix from $1,950 2018-05-09
Internet Graphics Server CRITICAL 9.8
CVE-2018-2420

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi…

Mitigation only
Fix from $2,300 2018-05-09
Internet Graphics Server HIGH 7.5
CVE-2018-2421

SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…

Mitigation only
Fix from $1,950 2018-05-09
Identity Management MEDIUM 5.4
CVE-2018-2416

SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.

Mitigation only
Fix from $1,600 2018-05-09
Identity Management MEDIUM 5.3
CVE-2018-2417

Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be re…

Mitigation only
Fix from $1,600 2018-05-09
Disclosure Management CRITICAL 9.8
CVE-2018-2404

SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.

Mitigation only
Fix from $2,300 2018-04-10
Cloud Platform HIGH 8.8
CVE-2018-2409

Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some othe…

Mitigation only
Fix from $1,950 2018-04-10
Disclosure Management HIGH 8.8
CVE-2018-2412

SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Mitigation only
Fix from $1,950 2018-04-10
Disclosure Management HIGH 8.8
CVE-2018-2413

SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Mitigation only
Fix from $1,950 2018-04-10
Businessobjects HIGH 7.3
CVE-2018-2408

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password ch…

Mitigation only
Fix from $1,950 2018-04-10
Disclosure Management MEDIUM 6.5
CVE-2018-2403

Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible…

Mitigation only
Fix from $1,600 2018-04-10
Solution Manager MEDIUM 5.4
CVE-2018-2405

SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lea…

Mitigation only
Fix from $1,600 2018-04-10
Business One MEDIUM 5.4
CVE-2018-2410

SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnera…

Mitigation only
Fix from $1,600 2018-04-10
Crystal Reports Server MEDIUM 5.3
CVE-2018-2406

Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup p…

Mitigation only
Fix from $1,600 2018-04-10
Hana HIGH 8.4
CVE-2018-2402

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & r…

Mitigation only
Fix from $1,950 2018-03-14
Business Client HIGH 7.5
CVE-2018-2398

Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.

No fix yet
Fix from $1,950 2018-03-14