Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Portal HIGH 7.5
CVE-2013-7367

SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via u…

Mitigation only
Fix from $1,950 2014-04-10
Enhancement Package HIGH 7.5
CVE-2014-2748

The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes …

Mitigation only
Fix from $1,950 2014-04-10
Software Deployment Manager MEDIUM 5.0
CVE-2013-7366

The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors relate…

No fix yet
Fix from $1,600 2014-04-10
Hana MEDIUM 5.0
CVE-2014-2749

The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive inf…

Mitigation only
Fix from $1,600 2014-04-10
Bi Universal Data Integration HIGH 7.5
CVE-2013-7355

SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL commands via unspecified vectors, r…

No fix yet
Fix from $1,950 2014-04-10
Adminadapter HIGH 7.5
CVE-2013-7360

Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown vectors.

Mitigation only
Fix from $1,950 2014-04-10
Ccms \/ Database Monitor MEDIUM 5.0
CVE-2013-7356

Unspecified vulnerability in the SAP CCMS / Database Monitors for Oracle allows attackers to obtain the database password via unknown vectors.

No fix yet
Fix from $1,600 2014-04-10
J2ee Engine MEDIUM 5.0
CVE-2013-7357

Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vector…

No fix yet
Fix from $1,600 2014-04-10
Guided Procedures Archive Monitor MEDIUM 5.0
CVE-2013-7358

Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other i…

Mitigation only
Fix from $1,600 2014-04-10
Mobile Infrastructure MEDIUM 5.0
CVE-2013-7359

Unspecified vulnerability in SAP Mobile Infrastructure allows remote attackers to obtain sensitive port information via unknown vectors, related to a…

No fix yet
Fix from $1,600 2014-04-10
Cm Services MEDIUM 5.0
CVE-2013-7361

Directory traversal vulnerability in SAP CMS and CM Services allows attackers to upload arbitrary files via unspecified vectors.

Mitigation only
Fix from $1,600 2014-04-10
Netweaver MEDIUM 5.0
CVE-2014-1960

The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecifie…

Mitigation only
Fix from $1,600 2014-02-14
Netweaver MEDIUM 5.0
CVE-2014-1961

Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack ve…

Mitigation only
Fix from $1,600 2014-02-14
Customer Relationship Management MEDIUM 5.0
CVE-2014-1962

Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE)…

Mitigation only
Fix from $1,600 2014-02-14
Netweaver MEDIUM 5.0
CVE-2014-1963

Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service via unknown attack vectors.

No fix yet
Fix from $1,600 2014-02-14
Emr Unwired HIGH 7.5
CVE-2013-7096

Multiple SQL injection vulnerabilities in SAP EMR Unwired allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

No fix yet
Fix from $1,950 2013-12-13
Customer Relationship Management HIGH 10.0
CVE-2013-7095

The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML Exter…

Mitigation only
Fix from $1,950 2013-12-13
Netweaver HIGH 7.5
CVE-2013-7094

SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands v…

Mitigation only
Fix from $1,950 2013-12-13
Network Interface Router MEDIUM 5.0
CVE-2013-7093

SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vecto…

Mitigation only
Fix from $1,600 2013-12-13
Netweaver HIGH 7.5
CVE-2013-6869

SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL comm…

Mitigation only
Fix from $1,950 2013-11-23
Netweaver HIGH 10.0
CVE-2013-6822

GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue.

Mitigation only
Fix from $1,950 2013-11-20
Netweaver MEDIUM 6.4
CVE-2013-6823

GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors.

No fix yet
Fix from $1,600 2013-11-20
Netweaver MEDIUM 5.0
CVE-2013-6821

Directory traversal vulnerability in the Exportability Check Service in SAP NetWeaver allows remote attackers to read arbitrary files via unspecified…

Mitigation only
Fix from $1,600 2013-11-20
Netweaver Development Infrastructure HIGH 9.3
CVE-2013-6820

Unrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers to execute arbitrary code by up…

Mitigation only
Fix from $1,950 2013-11-20
Network Interface Router MEDIUM 6.8
CVE-2013-6817

Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrar…

Mitigation only
Fix from $1,600 2013-11-20
Netweaver Logviewer MEDIUM 6.4
CVE-2013-6818

SAP NetWeaver Logviewer 6.30, when running on Windows, allows remote attackers to bypass intended access restrictions via unspecified vectors.

No fix yet
Fix from $1,600 2013-11-20
Erp Central Component HIGH 7.5
CVE-2013-6284

Unspecified vulnerability in the Statutory Reporting for Insurance (FS_SR) component in the Financial Services module for SAP ERP Central Component (…

Mitigation only
Fix from $1,950 2013-10-26
Erp Central Component MEDIUM 6.0
CVE-2013-3244

Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (EC…

Mitigation only
Fix from $1,600 2013-10-24
Netweaver MEDIUM 5.0
CVE-2013-5751

Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary files via unspecified vectors.

No fix yet
Fix from $1,600 2013-09-16
Netweaver HIGH 7.5
CVE-2013-5723

SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD…

Mitigation only
Fix from $1,950 2013-09-12