Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enjoysap HIGH 7.6
CVE-2007-3606EPSS 8%

Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote att…

No fix yet
Fix from $1,950 2007-07-06
Enjoysap MEDIUM 5.0
CVE-2007-3607

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) …

No fix yet
Fix from $1,600 2007-07-06
Enjoysap MEDIUM 5.0
CVE-2007-3608

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vecto…

No fix yet
Fix from $1,600 2007-07-06
Rfc Library HIGH 10.0
CVE-2007-1916EPSS 7%

Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2007-04-10
Rfc Library HIGH 10.0
CVE-2007-1917EPSS 7%

Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2007-04-10
Rfc Library HIGH 7.5
CVE-2007-1915

Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2007-04-10
Rfc Library MEDIUM 5.0
CVE-2007-1913

The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users an…

No fix yet
Fix from $1,600 2007-04-10
Rfc Library MEDIUM 5.0
CVE-2007-1918

The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC ser…

No fix yet
Fix from $1,600 2007-04-10
Sap Web Application Server MEDIUM 5.0
CVE-2006-6010EPSS 14%

SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceiv…

Mitigation only
Fix from $1,600 2006-11-21
Sap Web Application Server MEDIUM 5.0
CVE-2006-6011

Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers to cause a denial of service (enserver.exe crash)…

Mitigation only
Fix from $1,600 2006-11-21
Internet Transaction Server MEDIUM 6.8
CVE-2006-5114

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject ar…

No fix yet
Fix from $1,600 2006-10-03
Internet Graphics Server HIGH 7.5
CVE-2006-4133EPSS 6%

Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial o…

Mitigation only
Fix from $1,950 2006-08-14
Internet Graphics Server MEDIUM 5.0
CVE-2006-4134

Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attac…

No fix yet
Fix from $1,600 2006-08-14
Sap Web Application Server MEDIUM 6.4
CVE-2006-1039

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive au…

Mitigation only
Fix from $1,600 2006-03-07
Business Connector MEDIUM 6.4
CVE-2006-0732

Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullNa…

Mitigation only
Fix from $1,600 2006-02-16
Sap R 3 HIGH 7.5
CVE-2005-4815

SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before…

Mitigation only
Fix from $1,950 2005-12-31
Sap Web Application Server MEDIUM 5.0
CVE-2005-3633

HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitra…

No fix yet
Fix from $1,600 2005-11-16
Sap Web Application Server MEDIUM 5.0
CVE-2005-3634EPSS 18%

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to a…

No fix yet
Fix from $1,600 2005-11-16
Sap R 3 HIGH 7.5
CVE-2002-1577

SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2…

Mitigation only
Fix from $1,950 2004-04-15
Sap R 3 HIGH 7.5
CVE-2003-1035

The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a b…

Mitigation only
Fix from $1,950 2004-04-15
Mysap Business Suite HIGH 7.5
CVE-2003-1039

Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) M…

Mitigation only
Fix from $1,950 2004-04-15
Internet Transaction Server MEDIUM 6.8
CVE-2003-0749

Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arb…

No fix yet
Fix from $1,600 2003-10-20
Internet Transaction Server MEDIUM 5.0
CVE-2003-0747

wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as direct…

No fix yet
Fix from $1,600 2003-10-20
Internet Transaction Server MEDIUM 5.0
CVE-2003-0748EPSS 8%

Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary fi…

No fix yet
Fix from $1,600 2003-10-20