Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver MEDIUM 5.0
CVE-2013-3319EPSS 20%

The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted S…

Mitigation only
Fix from $1,600 2013-08-16
Production Planning And Control MEDIUM 6.5
CVE-2013-3062

The CP_RC_TRANSACTION_CALL_BY_SET function in the Engineering Workbench component in SAP Production Planning and Control allows remote authenticated …

Mitigation only
Fix from $1,600 2013-05-01
Basis Communication Services MEDIUM 6.0
CVE-2013-3063

SAP BASIS Communication Services 4.6B through 7.30 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

No fix yet
Fix from $1,600 2013-05-01
Erp Central Component MEDIUM 6.5
CVE-2013-3061

The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the S…

Mitigation only
Fix from $1,600 2013-05-01
Graphical User Interface MEDIUM 6.9
CVE-2011-5154

Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privile…

Mitigation only
Fix from $1,600 2012-09-06
Netweaver Abap HIGH 10.0
CVE-2012-4341EPSS 9%

Multiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and exe…

Mitigation only
Fix from $1,950 2012-08-15
Netweaver HIGH 9.3
CVE-2012-2611EPSS 42%

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EH…

No fix yet
Fix from $1,950 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remo…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote atta…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remo…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote a…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-1291

Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive in…

Mitigation only
Fix from $1,600 2012-02-23
Netweaver MEDIUM 5.0
CVE-2012-1292

Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Messa…

Mitigation only
Fix from $1,600 2012-02-23
Crystal Reports HIGH 9.3
CVE-2010-2590EPSS 47%

Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 S…

No fix yet
Fix from $1,950 2010-12-22
Netweaver Business Client HIGH 9.3
CVE-2010-4556EPSS 6%

Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to exec…

Mitigation only
Fix from $1,950 2010-12-17
Businessobjects HIGH 9.0
CVE-2010-3983

CmcApp in SAP BusinessObjects Enterprise XI 3.2 allows remote authenticated users to gain privileges via vectors involving the Program Job Server and…

No fix yet
Fix from $1,950 2010-10-18
Businessobjects MEDIUM 5.0
CVE-2010-3979

Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid use…

No fix yet
Fix from $1,600 2010-10-18
Businessobjects MEDIUM 5.0
CVE-2010-3982

SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentia…

No fix yet
Fix from $1,600 2010-10-18
Business One 2005 A HIGH 10.0
CVE-2009-4988EPSS 66%

Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary co…

No fix yet
Fix from $1,950 2010-08-25
Crystal Reports HIGH 10.0
CVE-2010-3032EPSS 6%

Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers…

Mitigation only
Fix from $1,950 2010-08-17
Maxdb HIGH 10.0
CVE-2010-1185EPSS 15%

Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an i…

No fix yet
Fix from $1,950 2010-03-29
Sap Kernel MEDIUM 5.0
CVE-2009-4603

Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Appli…

Mitigation only
Fix from $1,600 2010-01-12
Crystal Reports Server HIGH 10.0
CVE-2009-3345

Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco…

No fix yet
Fix from $1,950 2009-09-24
Crystal Reports Server HIGH 10.0
CVE-2009-3346

Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated b…

No fix yet
Fix from $1,950 2009-09-24
Crystal Reports Server MEDIUM 5.0
CVE-2009-3344

Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown …

No fix yet
Fix from $1,600 2009-09-24
Sapgui HIGH 9.3
CVE-2008-4387EPSS 16%

Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unk…

Mitigation only
Fix from $1,950 2008-11-10
Maxdb HIGH 9.3
CVE-2008-0307

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown…

Mitigation only
Fix from $1,950 2008-03-11
Maxdb MEDIUM 6.9
CVE-2008-0306

sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment vari…

Mitigation only
Fix from $1,600 2008-03-11
Saplpd HIGH 7.8
CVE-2006-7220

Unspecified vulnerability in SAP SAPLPD and SAPSPRINT allows remote attackers to cause a denial of service (application crash) via a certain print jo…

Mitigation only
Fix from $1,950 2007-07-10