Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver MEDIUM 5.0
CVE-2014-8592

Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process ter…

Mitigation only
Fix from $1,600 2014-11-04
Hana MEDIUM 6.0
CVE-2014-8313

Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via uns…

No fix yet
Fix from $1,600 2014-10-16
Businessobjects Explorer MEDIUM 5.0
CVE-2014-8315

polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allow…

Mitigation only
Fix from $1,600 2014-10-16
Businessobjects Explorer MEDIUM 5.0
CVE-2014-8316

XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrar…

No fix yet
Fix from $1,600 2014-10-16
Businessobjects HIGH 7.1
CVE-2014-8310

The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFact…

No fix yet
Fix from $1,950 2014-10-16
Businessobjects MEDIUM 5.0
CVE-2014-8309

SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depen…

Mitigation only
Fix from $1,600 2014-10-16
Netweaver MEDIUM 6.5
CVE-2014-6252

Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated …

Mitigation only
Fix from $1,600 2014-09-05
Crystal Reports MEDIUM 6.8
CVE-2014-5505

Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file.

Mitigation only
Fix from $1,600 2014-09-04
Crystal Reports MEDIUM 6.8
CVE-2014-5506

Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT fil…

Mitigation only
Fix from $1,600 2014-09-04
Solution Manager HIGH 7.5
CVE-2014-5175

The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a ve…

Mitigation only
Fix from $1,950 2014-07-31
Fi Manager Self Service MEDIUM 6.0
CVE-2014-5176

SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors.

No fix yet
Fix from $1,600 2014-07-31
Hana Extended Application Services MEDIUM 5.0
CVE-2014-5173

SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that w…

No fix yet
Fix from $1,600 2014-07-31
Supplier Relationship Management MEDIUM 5.8
CVE-2014-4159

Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbit…

No fix yet
Fix from $1,600 2014-06-13
Brazil MEDIUM 5.0
CVE-2014-4005

SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Oil Industry Solution Traders And Schedulers Workbench MEDIUM 5.0
CVE-2014-4006

The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain ac…

Mitigation only
Fix from $1,600 2014-06-09
Upgrade Tools MEDIUM 5.0
CVE-2014-4007

The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Web Services Tool MEDIUM 5.0
CVE-2014-4008

SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Computing Center Management System Monitoring MEDIUM 5.0
CVE-2014-4009

SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Transaction Data Pool MEDIUM 5.0
CVE-2014-4010

SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

No fix yet
Fix from $1,600 2014-06-09
Capacity Leveling MEDIUM 5.0
CVE-2014-4011

SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

No fix yet
Fix from $1,600 2014-06-09
Open Hub Service MEDIUM 5.0
CVE-2014-4012

SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Netweaver HIGH 7.5
CVE-2014-4003

The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system.

No fix yet
Fix from $1,950 2014-06-09
Project System MEDIUM 5.0
CVE-2014-4004

The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote …

No fix yet
Fix from $1,600 2014-06-09
Netweaver Software Lifecycle Manager MEDIUM 5.0
CVE-2014-3129

The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted …

Mitigation only
Fix from $1,600 2014-04-30
Netweaver Java Application Server MEDIUM 5.0
CVE-2014-3133

SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o…

Mitigation only
Fix from $1,600 2014-04-30
Print And Output Management HIGH 7.5
CVE-2014-2751

SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,950 2014-04-10
Business Object Processing Framework For Abap HIGH 7.5
CVE-2014-2752

SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via u…

Mitigation only
Fix from $1,950 2014-04-10
Ccms Agent HIGH 7.5
CVE-2013-7362

An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.

No fix yet
Fix from $1,950 2014-04-10
Solution Manager HIGH 7.5
CVE-2013-7363

Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the …

Mitigation only
Fix from $1,950 2014-04-10
Netweaver HIGH 7.5
CVE-2013-7364

An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri…

Mitigation only
Fix from $1,950 2014-04-10