Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2019-0284 SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attac… Hana Mitigation only Fix from $1,6002019-04-10 MEDIUM 5.3 CVE-2019-0282 Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed w… Netweaver Process Integration Mitigation only Fix from $1,6002019-04-10 HIGH 8.8 CVE-2019-0270 ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of p… Advanced Business Application Programming Platform Kernel Mitigation only Fix from $1,9502019-03-12 HIGH 8.8 CVE-2019-0276 Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorizatio… Banking Services From Sap Mitigation only Fix from $1,9502019-03-12 HIGH 8.1 CVE-2019-0268 SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepte… Businessobjects Business Intelligence Mitigation only Fix from $1,9502019-03-12 HIGH 7.5 CVE-2019-0274 SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service (i.e. den… Mobile Platform Sdk Mitigation only Fix from $1,9502019-03-12 MEDIUM 6.5 CVE-2019-0277 SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer w… Hana Extended Application Services Mitigation only Fix from $1,6002019-03-12 MEDIUM 5.4 CVE-2019-0269 SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resul… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-03-12 HIGH 8.8 CVE-2019-0267 SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This… Manufacturing Integration And Intelligence Mitigation only Fix from $1,9502019-02-15 HIGH 7.5 CVE-2019-0266 Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a … Hana Extended Application Services Mitigation only Fix from $1,9502019-02-15 CRITICAL 9.8 CVE-2019-0259 SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file for… Businessobjects Mitigation only Fix from $2,3002019-02-15 CRITICAL 9.8 CVE-2019-0261 Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for… Landscape Management Mitigation only Fix from $2,3002019-02-15 HIGH 8.8 CVE-2019-0258 SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privi… Disclosure Management Mitigation only Fix from $1,9502019-02-15 MEDIUM 5.4 CVE-2019-0262 SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cro… Businessobjects Bi Platform Mitigation only Fix from $1,6002019-02-15 HIGH 8.1 CVE-2019-0255 SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Serv… Advanced Business Application Programming Platform Kernel Mitigation only Fix from $1,9502019-02-15 MEDIUM 6.1 CVE-2019-0251 The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site… Businessobjects Mitigation only Fix from $1,6002019-02-15 MEDIUM 5.5 CVE-2019-0256 Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restr… Business One No fix yet Fix from $1,6002019-02-15 HIGH 7.5 CVE-2019-0249 Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted. Landscape Management Mitigation only Fix from $1,9502019-01-08 HIGH 8.8 CVE-2018-2484 SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.0… Sapscore Mitigation only Fix from $1,9502019-01-08 HIGH 8.8 CVE-2019-0243 Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform necessary authorization check… Bw\/4hana Mitigation only Fix from $1,9502019-01-08 HIGH 7.5 CVE-2018-2499 A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the passw… Financial Consolidation Cube Designer Mitigation only Fix from $1,9502019-01-08 HIGH 7.5 CVE-2019-0241 SAP Work and Inventory Manager (Agentry_SDK , before 7.0, 7.1) allows an attacker to prevent legitimate users from accessing a service, either by cra… Work Manager Mitigation only Fix from $1,9502019-01-08 MEDIUM 5.9 CVE-2019-0248 Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to acces… Netweaver Mitigation only Fix from $1,6002019-01-08 MEDIUM 5.4 CVE-2019-0244 SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inp… Customer Relationship Management Webclient Ui Mitigation only Fix from $1,6002019-01-08 MEDIUM 5.4 CVE-2019-0245 SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inp… Customer Relationship Management Webclient Ui Mitigation only Fix from $1,6002019-01-08 HIGH 7.4 CVE-2018-2503 By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been… Netweaver Application Server Java Mitigation only Fix from $1,9502018-12-11 HIGH 7.1 CVE-2018-2492 SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in ver… Netweaver Application Server Java Mitigation only Fix from $1,9502018-12-11 MEDIUM 6.1 CVE-2018-2502 TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using … Business One On Hana Mitigation only Fix from $1,6002018-12-11 MEDIUM 6.1 CVE-2018-2504 SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulatio… Netweaver Application Server Java Mitigation only Fix from $1,6002018-12-11 MEDIUM 6.1 CVE-2018-2505 SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are bas… Hybris Mitigation only Fix from $1,6002018-12-11