Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2020-6244 SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted… Business Client Mitigation only Fix from $1,9502020-05-12 HIGH 7.5 CVE-2020-6240 SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacke… Netweaver Application Server Abap Mitigation only Fix from $1,9502020-05-12 MEDIUM 6.1 CVE-2020-6213 SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulne… Netweaver As Abap Business Server Pages Mitigation only Fix from $1,6002020-04-24 MEDIUM 5.4 CVE-2020-6212 Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and… Erp Mitigation only Fix from $1,6002020-04-24 CRITICAL 9.8 CVE-2020-6195 SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002020-04-14 HIGH 8.8 CVE-2020-6225 SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not suffi… Netweaver Knowledge Management And Collaboration \(kmc Cm\) Mitigation only Fix from $1,9502020-04-14 MEDIUM 6.1 CVE-2020-6211 SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6215 SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker… Netweaver As Abap Business Server Pages No fix yet Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6217 SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficien… Netweaver As Abap Business Server Pages Mitigation only Fix from $1,6002020-04-14 CRITICAL 9.3 CVE-2020-6238 SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing … Commerce Cloud Mitigation only Fix from $2,3002020-04-14 HIGH 8.6 CVE-2020-6235 SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, … Solution Manager Mitigation only Fix from $1,9502020-04-14 HIGH 7.5 CVE-2020-6237 Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to acce… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502020-04-14 HIGH 7.2 CVE-2020-6234 SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying ope… Host Agent No fix yet Fix from $1,9502020-04-14 HIGH 7.2 CVE-2020-6236 SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership a… Adaptive Extensions Mitigation only Fix from $1,9502020-04-14 MEDIUM 5.3 CVE-2020-6232 SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This af… Commerce Cloud Mitigation only Fix from $1,6002020-04-14 HIGH 8.8 CVE-2020-6219 SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allo… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502020-04-14 HIGH 7.5 CVE-2020-6227 SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to s… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502020-04-14 HIGH 7.5 CVE-2020-6228 SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions … Business Client Mitigation only Fix from $1,9502020-04-14 HIGH 7.2 CVE-2020-6230 SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the applicat… Orientdb Mitigation only Fix from $1,9502020-04-14 MEDIUM 6.2 CVE-2020-6224 SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access u… Netweaver Application Server Java Mitigation only Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6216 SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in re… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6223 The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to incl… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6229 SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75… Netweaver As Abap Business Server Pages Mitigation only Fix from $1,6002020-04-14 MEDIUM 5.4 CVE-2020-6221 Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controll… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 5.4 CVE-2020-6222 SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlle… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 5.4 CVE-2020-6226 SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inpu… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 5.4 CVE-2020-6231 SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inpu… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 5.0 CVE-2020-6218 Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information tha… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-04-14 MEDIUM 6.1 CVE-2020-6210 SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag … Fiori Launchpad Mitigation only Fix from $1,6002020-03-10 CRITICAL 9.8 CVE-2020-6207 KEVEPSS 98% SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic… Solution Manager Mitigation only Fix from $2,3002020-03-10