Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver Java Web Application MEDIUM 6.1
CVE-2018-2371

The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in C…

Mitigation only
Fix from $1,600 2018-02-14
Hana MEDIUM 5.3
CVE-2018-2369

Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attac…

Mitigation only
Fix from $1,600 2018-02-14
Bi Launchpad MEDIUM 5.3
CVE-2018-2370

Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, …

Mitigation only
Fix from $1,600 2018-02-14
Solution Manager HIGH 8.8
CVE-2018-2361

In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required…

Mitigation only
Fix from $1,950 2018-01-09
Sap Kernel HIGH 7.5
CVE-2018-2360

SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause con…

Mitigation only
Fix from $1,950 2018-01-09
Hana MEDIUM 5.3
CVE-2018-2362

A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose informa…

Mitigation only
Fix from $1,600 2018-01-09
Business Intelligence Promotion Management Application CRITICAL 9.8
CVE-2017-16684

SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti…

Mitigation only
Fix from $2,300 2017-12-12
Sap Kernel HIGH 8.8
CVE-2017-16689

A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f…

Mitigation only
Fix from $1,950 2017-12-12
Plant Connectivity HIGH 7.8
CVE-2017-16690

A malicious DLL preload attack possible on NwSapSetup and Installation self-extracting program for SAP Plant Connectivity 2.3 and 15.0. It is possibl…

Mitigation only
Fix from $1,950 2017-12-12
Hana Extended Application Services HIGH 7.5
CVE-2017-16680

Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller servic…

Mitigation only
Fix from $1,950 2017-12-12
Businessobjects MEDIUM 6.5
CVE-2017-16683

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from acc…

Mitigation only
Fix from $1,600 2017-12-12
Business Application Software Integrated Solution MEDIUM 6.5
CVE-2017-16691

SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note…

Mitigation only
Fix from $1,600 2017-12-12
Sap Kernel MEDIUM 6.1
CVE-2017-16679

URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21…

Mitigation only
Fix from $1,600 2017-12-12
Business Intelligence Promotion Management Application MEDIUM 6.1
CVE-2017-16681

Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controll…

Mitigation only
Fix from $1,600 2017-12-12
Business Warehouse Universal Data Integration MEDIUM 6.1
CVE-2017-16685

Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient…

Mitigation only
Fix from $1,600 2017-12-12
Hana Database MEDIUM 5.3
CVE-2017-16687

The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,…

Mitigation only
Fix from $1,600 2017-12-12
Businessobjects Financial Consolidation MEDIUM 6.1
CVE-2017-14516

Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292.

Mitigation only
Fix from $1,600 2017-12-03
Point Of Sale Xpress Server CRITICAL 9.8
CVE-2017-15295

Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.

Mitigation only
Fix from $2,300 2017-10-16
Customer Relationship Management HIGH 8.8
CVE-2017-15296

The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.

No fix yet
Fix from $1,950 2017-10-16
Host Agent HIGH 7.5
CVE-2017-15297

SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.

Mitigation only
Fix from $1,950 2017-10-16
Point Of Sale Xpress Server CRITICAL 9.8
CVE-2017-15293

Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at…

Mitigation only
Fix from $2,300 2017-10-16
Customer Relationship Management MEDIUM 6.1
CVE-2017-15294

The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

Mitigation only
Fix from $1,600 2017-10-16
E Recruiting HIGH 7.5
CVE-2017-14511

An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/…

Mitigation only
Fix from $1,950 2017-09-17
Netweaver Application Server Java HIGH 7.5
CVE-2017-12637 KEVEPSS 95%

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a…

Mitigation only
Fix from $1,950 2017-08-07
Trex CRITICAL 9.8
CVE-2017-11459

SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr…

Mitigation only
Fix from $2,300 2017-07-25
Netweaver Application Server Java MEDIUM 6.5
CVE-2017-11457

XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o…

Mitigation only
Fix from $1,600 2017-07-25
Netweaver Application Server Java MEDIUM 6.1
CVE-2017-11458

Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary…

Mitigation only
Fix from $1,600 2017-07-25
Netweaver Portal MEDIUM 6.1
CVE-2017-11460

Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary …

Mitigation only
Fix from $1,600 2017-07-25
Netweaver HIGH 7.5
CVE-2017-9844EPSS 6%

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java…

Mitigation only
Fix from $1,950 2017-07-12
Netweaver HIGH 7.5
CVE-2017-9845

disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG reque…

Mitigation only
Fix from $1,950 2017-07-12