Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2018-2486 SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripti… Marketing Sapscore No fix yet Fix from $1,6002018-12-11 HIGH 8.8 CVE-2018-2477 Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an … Netweaver Mitigation only Fix from $1,9502018-11-13 HIGH 8.3 CVE-2018-2487 SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use c… Disclosure Management Mitigation only Fix from $1,9502018-11-13 MEDIUM 6.5 CVE-2018-2473 SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows a… Businessobjects Business Intelligence Mitigation only Fix from $1,6002018-11-13 MEDIUM 6.1 CVE-2018-2476 Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site. Netweaver Mitigation only Fix from $1,6002018-11-13 MEDIUM 6.1 CVE-2018-2479 SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resultin… Businessobjects Bi Platform Mitigation only Fix from $1,6002018-11-13 MEDIUM 6.5 CVE-2018-2474 SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended req… Fiori Mitigation only Fix from $1,6002018-10-09 HIGH 7.5 CVE-2018-2468 Under certain conditions the backup server in SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information … Adaptive Server Enterprise Mitigation only Fix from $1,9502018-10-09 HIGH 7.5 CVE-2018-2469 Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise… Adaptive Server Enterprise Mitigation only Fix from $1,9502018-10-09 HIGH 7.5 CVE-2018-2471 Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherw… Businessobjects Business Intelligence Platform No fix yet Fix from $1,9502018-10-09 MEDIUM 6.1 CVE-2018-2472 SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs,… Businessobjects Bi Platform Mitigation only Fix from $1,6002018-10-09 MEDIUM 5.3 CVE-2018-2467 In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser su… Businessobjects Bi Platform Mitigation only Fix from $1,6002018-10-09 MEDIUM 5.4 CVE-2018-2466 In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate user-controlled inputs, which… Data Services Mitigation only Fix from $1,6002018-10-09 HIGH 7.5 CVE-2018-2465 SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauth… Hana Mitigation only Fix from $1,9502018-09-11 MEDIUM 6.1 CVE-2018-2464 SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scri… Netweaver Mitigation only Fix from $1,6002018-09-11 HIGH 8.8 CVE-2018-2461 Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of p… People Profile Mitigation only Fix from $1,9502018-09-11 HIGH 8.8 CVE-2018-2462 In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML doc… Netweaver Mitigation only Fix from $1,9502018-09-11 HIGH 7.5 CVE-2018-2458 Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which… Business One No fix yet Fix from $1,9502018-09-11 HIGH 7.5 CVE-2018-2459 Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occ… Mobile Platform Mitigation only Fix from $1,9502018-09-11 MEDIUM 6.5 CVE-2018-2457 Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access information which would otherwise be re… Adaptive Server Enterprise No fix yet Fix from $1,6002018-09-11 MEDIUM 5.9 CVE-2018-2460 SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM att… Business One Mitigation only Fix from $1,6002018-09-11 HIGH 8.8 CVE-2018-2454 SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary aut… Enterprise Financial Services Mitigation only Fix from $1,9502018-09-11 HIGH 8.8 CVE-2018-2455 SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary … Enterprise Financial Services Mitigation only Fix from $1,9502018-09-11 MEDIUM 6.1 CVE-2018-2452 The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, result… Netweaver Application Server Java Mitigation only Fix from $1,6002018-09-11 HIGH 8.6 CVE-2018-2449 SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid reposito… Supplier Relationship Management Mdm Catalog Mitigation only Fix from $1,9502018-08-14 HIGH 7.5 CVE-2018-2446 Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name… Businessobjects Business Intelligence Mitigation only Fix from $1,9502018-08-14 HIGH 7.2 CVE-2018-2450 SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore re… Maxdb Mitigation only Fix from $1,9502018-08-14 MEDIUM 6.5 CVE-2018-2447 SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposi… Businessobjects Business Intelligence Mitigation only Fix from $1,6002018-08-14 MEDIUM 5.3 CVE-2018-2448 Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user exis… Supplier Relationship Management Mdm Catalog Mitigation only Fix from $1,6002018-08-14 CRITICAL 9.6 CVE-2018-2445 AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft… Businessobjects Business Intelligence Mitigation only Fix from $2,3002018-08-14