Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-6368 SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modif… Business Planning And Consolidation Mitigation only Fix from $1,6002020-10-15 MEDIUM 6.5 CVE-2020-6311 Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per… Bank Analyzer Mitigation only Fix from $1,6002020-09-09 MEDIUM 6.1 CVE-2020-6324 SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacke… Netweaver As Abap Business Server Pages Mitigation only Fix from $1,6002020-09-09 HIGH 8.1 CVE-2020-6320 SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of … Marketing Mitigation only Fix from $1,9502020-09-09 HIGH 7.2 CVE-2020-6318EPSS 6% A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi… Abap Platform No fix yet Fix from $1,9502020-09-09 MEDIUM 6.5 CVE-2020-6321 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,6002020-09-09 MEDIUM 5.4 CVE-2020-6326 SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked… Netweaver Knowledge Management Mitigation only Fix from $1,6002020-09-09 HIGH 8.1 CVE-2020-6302 SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacke… Commerce Mitigation only Fix from $1,9502020-09-09 MEDIUM 6.5 CVE-2020-6313 SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an… Netweaver Application Server Java Mitigation only Fix from $1,6002020-09-09 MEDIUM 6.1 CVE-2020-6283 SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad ht… Fiori Launchpad Mitigation only Fix from $1,6002020-09-09 MEDIUM 5.4 CVE-2020-6312 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrati… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-09-09 MEDIUM 5.3 CVE-2020-6288 SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-09-09 CRITICAL 9.1 CVE-2020-6294 Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002020-08-12 HIGH 8.8 CVE-2020-6296 SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject co… Abap Platform Mitigation only Fix from $1,9502020-08-12 HIGH 8.1 CVE-2020-6298 SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Marke… Generic Market Data Mitigation only Fix from $1,9502020-08-12 HIGH 8.1 CVE-2020-6301 SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify… Hcm Travel Management No fix yet Fix from $1,9502020-08-12 HIGH 7.8 CVE-2020-6295 Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat… Adaptive Server Enterprise Mitigation only Fix from $1,9502020-08-12 HIGH 7.5 CVE-2020-6309 SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authent… Netweaver Application Server Java Mitigation only Fix from $1,9502020-08-12 CRITICAL 9.0 CVE-2020-6284 SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to ina… Netweaver Knowledge Management Mitigation only Fix from $2,3002020-08-12 MEDIUM 6.5 CVE-2020-6293 SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to ac… Netweaver Knowledge Management Mitigation only Fix from $1,6002020-08-12 CRITICAL 10.0 CVE-2020-6287 KEVEPSS 95% SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker… Netweaver Application Server Java Mitigation only Fix from $2,3002020-07-14 HIGH 8.8 CVE-2020-6289 SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to brow… Disclosure Management Mitigation only Fix from $1,9502020-07-14 HIGH 8.8 CVE-2020-6291 SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating o… Disclosure Management Mitigation only Fix from $1,9502020-07-14 HIGH 8.8 CVE-2020-6292 Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expirati… Disclosure Management Mitigation only Fix from $1,9502020-07-14 MEDIUM 6.3 CVE-2020-6290 SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session… Disclosure Management Mitigation only Fix from $1,6002020-07-14 MEDIUM 6.5 CVE-2020-6285 SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to… Netweaver Mitigation only Fix from $1,6002020-07-14 MEDIUM 6.1 CVE-2020-6276 SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-07-14 MEDIUM 6.1 CVE-2020-6281 SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting refle… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-07-14 MEDIUM 5.8 CVE-2020-6282 SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-… Netweaver Application Server Java Mitigation only Fix from $1,6002020-07-14 MEDIUM 5.4 CVE-2020-6267 Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag. Disclosure Management Mitigation only Fix from $1,6002020-07-14