Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Hana CRITICAL 9.8
CVE-2016-6150

The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended ac…

No fix yet
Fix from $2,300 2016-08-05
Hana Sps09 MEDIUM 5.5
CVE-2016-6149

SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Se…

No fix yet
Fix from $1,600 2016-08-05
Hana HIGH 7.5
CVE-2016-6148

SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors relate…

No fix yet
Fix from $1,950 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6147

An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified…

No fix yet
Fix from $2,300 2016-08-05
Hana Db MEDIUM 5.3
CVE-2016-6145

The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username…

No fix yet
Fix from $1,600 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6140EPSS 6%

SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591.

No fix yet
Fix from $2,300 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6139

SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.

No fix yet
Fix from $2,300 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6138EPSS 6%

Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Secur…

No fix yet
Fix from $2,300 2016-08-05
Hana Db MEDIUM 5.5
CVE-2016-3640

The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obtain sensitive password informa…

Mitigation only
Fix from $1,600 2016-08-05
Hana HIGH 7.5
CVE-2016-4017

The Data Provisioning Agent (aka DP Agent) in SAP HANA allows remote attackers to cause a denial of service (process crash) via unspecified vectors, …

Mitigation only
Fix from $1,950 2016-04-14
Hana HIGH 7.3
CVE-2016-4018

The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to o…

Mitigation only
Fix from $1,950 2016-04-14
Java As MEDIUM 6.1
CVE-2016-4016

Cross-site scripting (XSS) vulnerability in SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) 15 allows remote attackers to inj…

No fix yet
Fix from $1,600 2016-04-14
Netweaver HIGH 7.5
CVE-2016-4015

The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted reques…

Mitigation only
Fix from $1,950 2016-04-14
Netweaver HIGH 8.6
CVE-2016-4014EPSS 5%

XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (syst…

No fix yet
Fix from $1,950 2016-04-14
Java As HIGH 7.5
CVE-2016-3979EPSS 6%

Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory co…

No fix yet
Fix from $1,950 2016-04-08
Netweaver Application Server Java HIGH 8.8
CVE-2015-8840

The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sen…

Mitigation only
Fix from $1,950 2016-04-08
3d Visual Enterprise Viewer HIGH 8.8
CVE-2016-2536

Multiple use-after-free vulnerabilities in SAP 3D Visual Enterprise Viewer allow remote attackers to execute arbitrary code via a crafted SketchUp do…

Mitigation only
Fix from $1,950 2016-02-22
Netweaver HIGH 7.5
CVE-2016-2389EPSS 41%

Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP Net…

No fix yet
Fix from $1,950 2016-02-16
Netweaver MEDIUM 6.1
CVE-2016-2387

Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inje…

No fix yet
Fix from $1,600 2016-02-16
Netweaver Application Server Java CRITICAL 9.8
CVE-2016-2386 KEVEPSS 71%

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspec…

Mitigation only
Fix from $2,300 2016-02-16
Hana CRITICAL 9.3
CVE-2016-1929

The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption an…

Mitigation only
Fix from $2,300 2016-01-20
Hana CRITICAL 9.8
CVE-2016-1928EPSS 6%

Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a craft…

Mitigation only
Fix from $2,300 2016-01-20
Netweaver MEDIUM 6.1
CVE-2016-1911

Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors re…

Mitigation only
Fix from $1,600 2016-01-15
Netweaver MEDIUM 5.3
CVE-2016-1910EPSS 6%

The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

No fix yet
Fix from $1,600 2016-01-15
Afaria CRITICAL 9.1
CVE-2015-8753

SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insec…

Mitigation only
Fix from $2,300 2016-01-08
Mobile Platform HIGH 7.5
CVE-2015-8600

The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive information, gain privileges…

Mitigation only
Fix from $1,950 2015-12-17
Plant Connectivity HIGH 7.8
CVE-2015-8330

The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption and agent crash) via crafted xM…

No fix yet
Fix from $1,950 2015-11-24
Manufacturing Integration And Intelligence MEDIUM 5.0
CVE-2015-8329

SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct down…

No fix yet
Fix from $1,600 2015-11-24
Hana HIGH 7.5
CVE-2015-7994

The SQL interface in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via unspecified vectors related t…

No fix yet
Fix from $1,950 2015-11-10
Hana HIGH 7.5
CVE-2015-7993

The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary …

No fix yet
Fix from $1,950 2015-11-10