Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2019-0396 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently valida… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502019-11-13 MEDIUM 6.3 CVE-2019-0386 Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1… Erp Sales Mitigation only Fix from $1,6002019-11-13 MEDIUM 5.3 CVE-2019-0388 SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content d… Ui Mitigation only Fix from $1,6002019-11-13 HIGH 8.8 CVE-2019-0389 An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privile… Netweaver Application Server Java Mitigation only Fix from $1,9502019-11-13 HIGH 7.5 CVE-2019-0350 SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP… Hana Database Mitigation only Fix from $1,9502019-11-04 MEDIUM 6.5 CVE-2019-0370 Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere wi… Financial Consolidation Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.5 CVE-2019-0381 A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can resul… Dynamic Tier Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0369 SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute … Financial Consolidation Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0374 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0375 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0376 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0377 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controll… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0378 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlle… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.3 CVE-2019-0379 SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security pro… Process Integration Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0368 SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does… Customer Relationship Management Bbpcrm Mitigation only Fix from $1,6002019-10-08 HIGH 7.5 CVE-2019-0365 SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22… Sap Kernel Mitigation only Fix from $1,9502019-09-10 MEDIUM 6.7 CVE-2019-0357 The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges. Hana Mitigation only Fix from $1,6002019-09-10 MEDIUM 6.1 CVE-2019-0361 SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode us… Supplier Relationship Management Mitigation only Fix from $1,6002019-09-10 HIGH 7.5 CVE-2019-0352 In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502019-09-10 HIGH 7.2 CVE-2019-0355 SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6… Netweaver Application Server Java Mitigation only Fix from $1,9502019-09-10 HIGH 7.2 CVE-2019-0349 SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.… Advanced Business Application Programming Platform Kernel Mitigation only Fix from $1,9502019-08-14 CRITICAL 9.8 CVE-2019-0344 KEVEPSS 7% Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex… Commerce Cloud Mitigation only Fix from $2,3002019-08-14 CRITICAL 9.8 CVE-2019-0345 A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30… Netweaver Application Server Java Mitigation only Fix from $2,3002019-08-14 HIGH 8.8 CVE-2019-0341 The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the a… Enable Now Mitigation only Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-0343 SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject … Commerce Cloud Mitigation only Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-0351 A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Becau… Netweaver Mitigation only Fix from $1,9502019-08-14 MEDIUM 6.5 CVE-2019-0346 Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.5 CVE-2019-0348 SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if th… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.1 CVE-2019-0337 Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled in… Netweaver Process Integration Mitigation only Fix from $1,6002019-08-14 MEDIUM 5.3 CVE-2019-0338 During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set,… Gateway Mitigation only Fix from $1,6002019-08-14