Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Successfactors MEDIUM 5.4
CVE-2017-9613

Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web …

No fix yet
Fix from $1,600 2017-06-15
Business One CRITICAL 9.6
CVE-2016-6256EPSS 8%

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell…

No fix yet
Fix from $2,300 2017-05-26
Netweaver Application Server Java HIGH 8.8
CVE-2017-8913

The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks…

Mitigation only
Fix from $1,950 2017-05-23
Hana Xs HIGH 8.3
CVE-2017-8914

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user …

Mitigation only
Fix from $1,950 2017-05-23
Hana Xs HIGH 7.5
CVE-2017-8915

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing …

Mitigation only
Fix from $1,950 2017-05-23
Sapcar HIGH 7.8
CVE-2017-8852

SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted r…

No fix yet
Fix from $1,950 2017-05-10
Netweaver Application Server Java HIGH 8.8
CVE-2017-7717

SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users…

Mitigation only
Fix from $1,950 2017-04-14
Sso Authentication Library HIGH 7.5
CVE-2017-7696EPSS 36%

SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in t…

Mitigation only
Fix from $1,950 2017-04-14
Business Intelligence Platform CRITICAL 9.8
CVE-2016-6818

SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify…

Mitigation only
Fix from $2,300 2017-04-13
Hana CRITICAL 9.8
CVE-2016-6143

SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

Mitigation only
Fix from $2,300 2017-04-13
Trex CRITICAL 9.8
CVE-2017-7691

A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.

Mitigation only
Fix from $2,300 2017-04-11
Netweaver CRITICAL 9.8
CVE-2016-10311

Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to t…

Mitigation only
Fix from $2,300 2017-04-10
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-10304

The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and ser…

Mitigation only
Fix from $1,600 2017-04-10
Gui For Windows CRITICAL 9.8
CVE-2017-6950

SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, a…

Mitigation only
Fix from $2,300 2017-03-23
Sap Kernel HIGH 7.5
CVE-2017-5997

The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash…

Mitigation only
Fix from $1,950 2017-02-15
Netweaver HIGH 7.5
CVE-2017-5372

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system informati…

No fix yet
Fix from $1,950 2017-01-23
Solution Manager HIGH 7.5
CVE-2016-10005

Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~t…

No fix yet
Fix from $1,950 2016-12-19
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-9563 KEVEPSS 24%

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi…

Mitigation only
Fix from $1,600 2016-11-23
Netweaver Application Server Java HIGH 7.5
CVE-2016-9562

SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the …

Mitigation only
Fix from $1,950 2016-11-23
Sapcryptolib MEDIUM 6.5
CVE-2016-4407

The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to imperson…

Mitigation only
Fix from $1,600 2016-10-13
Sapconsole HIGH 7.8
CVE-2016-3946

SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note …

Mitigation only
Fix from $1,950 2016-10-13
Sld Registration MEDIUM 5.5
CVE-2016-3638

SAP SLD Registration Program (aka SLDREG) allows local users to cause a denial of service (memory corruption and process termination) via a crafted H…

No fix yet
Fix from $1,600 2016-10-13
Netweaver HIGH 7.5
CVE-2016-3635

SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remot…

Mitigation only
Fix from $1,950 2016-10-13
Netweaver CRITICAL 9.1
CVE-2016-7435

The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.…

Mitigation only
Fix from $2,300 2016-10-05
Netweaver HIGH 7.5
CVE-2016-4551

The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to …

Mitigation only
Fix from $1,950 2016-10-05
Trex MEDIUM 5.3
CVE-2016-6146

The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security No…

No fix yet
Fix from $1,600 2016-09-27
Trex CRITICAL 9.8
CVE-2016-6137

An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security N…

No fix yet
Fix from $2,300 2016-09-27
Hana HIGH 7.5
CVE-2016-6142

SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to th…

No fix yet
Fix from $1,950 2016-09-26
Sapcar Archive Tool MEDIUM 5.8
CVE-2016-5847

SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted…

No fix yet
Fix from $1,600 2016-08-13
Sapcar MEDIUM 5.5
CVE-2016-5845

SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (prog…

No fix yet
Fix from $1,600 2016-08-13