Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Process Monitoring Infrastructure MEDIUM 6.1
CVE-2018-2399

Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user contr…

Mitigation only
Fix from $1,600 2018-03-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2018-2397

In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode use…

Mitigation only
Fix from $1,600 2018-03-14
Netweaver System Landscape Directory CRITICAL 9.8
CVE-2018-2368

SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that r…

Mitigation only
Fix from $2,300 2018-03-01
Customer Relationship Management MEDIUM 6.6
CVE-2018-2380 KEVEPSS 29%

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus charact…

Mitigation only
Fix from $1,600 2018-03-01
Netweaver Portal MEDIUM 6.1
CVE-2018-2365

SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting …

Mitigation only
Fix from $1,600 2018-03-01
Internet Graphics Server HIGH 8.8
CVE-2018-2395

Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite e…

Mitigation only
Fix from $1,950 2018-02-14
Internet Graphics Server HIGH 7.5
CVE-2018-2392EPSS 41%

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus…

Mitigation only
Fix from $1,950 2018-02-14
Internet Graphics Server HIGH 7.5
CVE-2018-2393EPSS 15%

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus…

Mitigation only
Fix from $1,950 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2384

Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics …

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2385

Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Serv…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2386

Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from accessing the SAP Internet Gra…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2387

A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to obtain information on ports, wh…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2390

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2391

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2394

Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, …

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2396

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.…

No fix yet
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.1
CVE-2018-2383

Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.1
CVE-2018-2388

Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 5.7
CVE-2018-2389

Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding importa…

Mitigation only
Fix from $1,600 2018-02-14
Erp Financials Information System HIGH 8.8
CVE-2018-2381

SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.0…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services HIGH 8.1
CVE-2018-2375

In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application e…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services HIGH 8.1
CVE-2018-2376

In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application e…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services HIGH 7.5
CVE-2018-2373

Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that del…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2372

A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL…

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2374

In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive app…

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2377

In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2378

In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumpti…

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2379

In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a spe…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2382

A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled …

Mitigation only
Fix from $1,600 2018-02-14
Customer Relationship Management Webclient Ui MEDIUM 6.1
CVE-2018-2364

SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in C…

Mitigation only
Fix from $1,600 2018-02-14