Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2020-6244
SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted…
Business Client
Mitigation only
HIGH 7.5
CVE-2020-6240
SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacke…
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.1
CVE-2020-6213
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulne…
Netweaver As Abap Business Server Pages
Mitigation only
MEDIUM 5.4
CVE-2020-6212
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and…
Erp
Mitigation only
CRITICAL 9.8
CVE-2020-6195
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 8.8
CVE-2020-6225
SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not suffi…
Netweaver Knowledge Management And Collaboration \(kmc Cm\)
Mitigation only
MEDIUM 6.1
CVE-2020-6211
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to …
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2020-6215
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker…
Netweaver As Abap Business Server Pages
No fix yet
MEDIUM 6.1
CVE-2020-6217
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficien…
Netweaver As Abap Business Server Pages
Mitigation only
CRITICAL 9.3
CVE-2020-6238
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing …
Commerce Cloud
Mitigation only
HIGH 8.6
CVE-2020-6235
SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, …
Solution Manager
Mitigation only
HIGH 7.5
CVE-2020-6237
Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to acce…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.2
CVE-2020-6234
SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying ope…
Host Agent
No fix yet
HIGH 7.2
CVE-2020-6236
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership a…
Adaptive Extensions
Mitigation only
MEDIUM 5.3
CVE-2020-6232
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This af…
Commerce Cloud
Mitigation only
HIGH 8.8
CVE-2020-6219
SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allo…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2020-6227
SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to s…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 7.5
CVE-2020-6228
SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions …
Business Client
Mitigation only
HIGH 7.2
CVE-2020-6230
SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the applicat…
Orientdb
Mitigation only
MEDIUM 6.2
CVE-2020-6224
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access u…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2020-6216
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in re…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2020-6223
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to incl…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2020-6229
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75…
Netweaver As Abap Business Server Pages
Mitigation only
MEDIUM 5.4
CVE-2020-6221
Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controll…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.4
CVE-2020-6222
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlle…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.4
CVE-2020-6226
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inpu…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.4
CVE-2020-6231
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inpu…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.0
CVE-2020-6218
Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information tha…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.1
CVE-2020-6210
SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag …
Fiori Launchpad
Mitigation only
CRITICAL 9.8
CVE-2020-6207 KEVEPSS 98%
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic…
Solution Manager
Mitigation only