Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mobile Platform MEDIUM 5.0
CVE-2015-2818

XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SA…

Mitigation only
Fix from $1,600 2015-04-01
Netweaver MEDIUM 5.0
CVE-2015-2817

The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Secu…

No fix yet
Fix from $1,600 2015-04-01
Afaria HIGH 7.5
CVE-2015-2816

The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted req…

No fix yet
Fix from $1,950 2015-04-01
Netweaver MEDIUM 6.5
CVE-2015-2815

Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remo…

No fix yet
Fix from $1,600 2015-04-01
Clinical Task Tracker MEDIUM 6.4
CVE-2015-2814

SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which…

Mitigation only
Fix from $1,600 2015-04-01
Netweaver Enterprise Portal MEDIUM 5.0
CVE-2015-2812

XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests …

No fix yet
Fix from $1,600 2015-04-01
Mobile Platform MEDIUM 5.0
CVE-2015-2813

XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP …

No fix yet
Fix from $1,600 2015-04-01
Netweaver Enterprise Portal MEDIUM 5.0
CVE-2015-2811

XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intr…

No fix yet
Fix from $1,600 2015-04-01
Businessobjects Edge MEDIUM 5.0
CVE-2015-2076

The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note …

No fix yet
Fix from $1,600 2015-02-27
Businessobjects Edge MEDIUM 5.0
CVE-2015-2075

SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011…

No fix yet
Fix from $1,600 2015-02-27
Enterprise Resource Planning HIGH 7.5
CVE-2015-1312

The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and p…

Mitigation only
Fix from $1,950 2015-01-22
Hana Extended Application Services HIGH 10.0
CVE-2015-1311

The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 209890…

Mitigation only
Fix from $1,950 2015-01-22
Sap Kernel MEDIUM 6.5
CVE-2014-9595

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…

Mitigation only
Fix from $1,600 2015-01-15
Sap Kernel MEDIUM 6.5
CVE-2014-9594

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…

Mitigation only
Fix from $1,600 2015-01-15
Businessobjects HIGH 10.0
CVE-2014-9387

SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORB…

Mitigation only
Fix from $1,950 2014-12-17
Sql Anywhere HIGH 7.5
CVE-2014-9264

Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alia…

Mitigation only
Fix from $1,950 2014-12-11
Governance Risk And Compliance HIGH 9.0
CVE-2013-3678

Multiple unspecified vulnerabilities in SAP Governance, Risk, and Compliance (GRC) allow remote authenticated users to gain privileges and execute ar…

No fix yet
Fix from $1,950 2014-11-19
Customer Relationship Management Internet Sales HIGH 10.0
CVE-2014-8661

The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Customer Relationship Management HIGH 10.0
CVE-2014-8669EPSS 5%

The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Payroll Process HIGH 7.8
CVE-2014-8662

Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors related to session handling.

No fix yet
Fix from $1,950 2014-11-06
Netweaver Business Warehouse HIGH 7.5
CVE-2014-8663

SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands …

Mitigation only
Fix from $1,950 2014-11-06
Environment Health And Safety HIGH 7.5
CVE-2014-8664

SQL injection vulnerability in Product Safety (EHS-SAF) component in SAP Environment, Health, and Safety Management allows remote attackers to execut…

Mitigation only
Fix from $1,950 2014-11-06
Contract Accounting HIGH 7.5
CVE-2014-8668

SQL injection vulnerability in SAP Contract Accounting allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Document Management Services HIGH 7.2
CVE-2014-8660

SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Environment Health And Safety MEDIUM 5.0
CVE-2014-8659

Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files via unspecified vectors.

Mitigation only
Fix from $1,600 2014-11-06
Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8665

The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.

Mitigation only
Fix from $1,600 2014-11-06
Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8666

The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain …

Mitigation only
Fix from $1,600 2014-11-06
Hana HIGH 7.5
CVE-2014-8588

SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL commands via unspecified vec…

Mitigation only
Fix from $1,950 2014-11-04
Network Interface Router MEDIUM 5.0
CVE-2014-8589

Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via cra…

Mitigation only
Fix from $1,600 2014-11-04
Netweaver MEDIUM 5.0
CVE-2014-8591

Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a deni…

No fix yet
Fix from $1,600 2014-11-04