Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2021-27600
SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parame…
Manufacturing Execution
Mitigation only
MEDIUM 5.4
CVE-2021-27601
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a…
Netweaver Application Server Java
Mitigation only
MEDIUM 5.3
CVE-2021-27598
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ…
Netweaver Application Server Java
Mitigation only
HIGH 8.3
CVE-2021-21482
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the …
Netweaver Master Data Management
Mitigation only
MEDIUM 6.5
CVE-2021-21485
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow …
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2021-21491
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attack…
Netweaver Application Server Java
Mitigation only
HIGH 7.8
CVE-2021-27585
When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer versi…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27586
When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version …
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27587
When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, t…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27588
When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27589
When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27590
When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27591
When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27592
When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes a…
3d Visual Enterprise Viewer
Mitigation only
HIGH 8.8
CVE-2021-21487
SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Payment Engine
Mitigation only
MEDIUM 6.5
CVE-2021-21488
Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w…
Netweaver Knowledge Management
Mitigation only
CRITICAL 9.8
CVE-2021-21484
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi…
Hana
Mitigation only
HIGH 8.8
CVE-2021-21480EPSS 51%
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a r…
Manufacturing Integration And Intelligence
No fix yet
HIGH 8.8
CVE-2021-21481
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This…
Netweaver
Mitigation only
HIGH 8.8
CVE-2021-21486
SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz…
Enterprise Financial Services
Mitigation only
CRITICAL 9.9
CVE-2021-21477EPSS 30%
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attack…
Commerce
Mitigation only
HIGH 8.8
CVE-2021-21472
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installati…
Software Provisioning Manager
Mitigation only
HIGH 7.5
CVE-2021-21475
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation …
Netweaver Master Data Management Server
Mitigation only
MEDIUM 6.5
CVE-2021-21474
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion is…
Hana Database
Mitigation only
MEDIUM 6.1
CVE-2021-21444
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 6.1
CVE-2021-21478
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
Web Dynpro Abap
Mitigation only
HIGH 7.5
CVE-2021-21469
When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an e…
Netweaver Master Data Management
Mitigation only
MEDIUM 6.5
CVE-2021-21468
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allow…
Business Warehouse
No fix yet
CRITICAL 9.9
CVE-2021-21465
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker …
Business Warehouse
No fix yet
HIGH 8.8
CVE-2021-21453
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of…
3d Visual Enterprise Viewer
Mitigation only