Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-2442 In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session … Businessobjects Business Intelligence Mitigation only Fix from $1,9502018-08-14 MEDIUM 6.1 CVE-2018-2444 SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script… Businessobjects Financial Consolidation Mitigation only Fix from $1,6002018-08-14 MEDIUM 5.5 CVE-2018-2441 Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unico… Sap Kernel No fix yet Fix from $1,6002018-08-14 HIGH 8.1 CVE-2017-16349 An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e… Business Planning And Consolidation Mitigation only Fix from $1,9502018-08-02 CRITICAL 9.1 CVE-2018-2437 The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can l… Internet Graphics Server Mitigation only Fix from $2,3002018-07-10 HIGH 8.8 CVE-2018-2436 Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting i… R\/3 Enterprise Retail Mitigation only Fix from $1,9502018-07-10 HIGH 7.5 CVE-2018-2438 The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prev… Internet Graphics Server Mitigation only Fix from $1,9502018-07-10 MEDIUM 5.9 CVE-2018-2439 The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is valid… Internet Graphics Server Mitigation only Fix from $1,6002018-07-10 HIGH 7.5 CVE-2018-2433 SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.2… Sap Kernel Mitigation only Fix from $1,9502018-07-10 HIGH 7.5 CVE-2018-2424 SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to th… Hana Database Mitigation only Fix from $1,9502018-06-12 MEDIUM 5.5 CVE-2018-2425 Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be r… Business One Mitigation only Fix from $1,6002018-06-12 MEDIUM 5.3 CVE-2018-2428 Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected a… Infrastructure Mitigation only Fix from $1,6002018-06-12 MEDIUM 6.1 CVE-2018-11415EPSS 8% SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indic… Internet Transaction Server No fix yet Fix from $1,6002018-05-24 HIGH 7.5 CVE-2018-2422 SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv… Internet Graphics Server Mitigation only Fix from $1,9502018-05-09 HIGH 7.5 CVE-2018-2423 SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from access… Internet Graphics Server Mitigation only Fix from $1,9502018-05-09 CRITICAL 9.8 CVE-2018-2420 SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi… Internet Graphics Server Mitigation only Fix from $2,3002018-05-09 HIGH 7.5 CVE-2018-2421 SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv… Internet Graphics Server Mitigation only Fix from $1,9502018-05-09 MEDIUM 5.4 CVE-2018-2416 SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source. Identity Management Mitigation only Fix from $1,6002018-05-09 MEDIUM 5.3 CVE-2018-2417 Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be re… Identity Management Mitigation only Fix from $1,6002018-05-09 CRITICAL 9.8 CVE-2018-2404 SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation. Disclosure Management Mitigation only Fix from $2,3002018-04-10 HIGH 8.8 CVE-2018-2409 Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some othe… Cloud Platform Mitigation only Fix from $1,9502018-04-10 HIGH 8.8 CVE-2018-2412 SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Disclosure Management Mitigation only Fix from $1,9502018-04-10 HIGH 8.8 CVE-2018-2413 SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Disclosure Management Mitigation only Fix from $1,9502018-04-10 HIGH 7.3 CVE-2018-2408 Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password ch… Businessobjects Mitigation only Fix from $1,9502018-04-10 MEDIUM 6.5 CVE-2018-2403 Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible… Disclosure Management Mitigation only Fix from $1,6002018-04-10 MEDIUM 5.4 CVE-2018-2405 SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lea… Solution Manager Mitigation only Fix from $1,6002018-04-10 MEDIUM 5.4 CVE-2018-2410 SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnera… Business One Mitigation only Fix from $1,6002018-04-10 MEDIUM 5.3 CVE-2018-2406 Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup p… Crystal Reports Server Mitigation only Fix from $1,6002018-04-10 HIGH 8.4 CVE-2018-2402 In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & r… Hana Mitigation only Fix from $1,9502018-03-14 HIGH 7.5 CVE-2018-2398 Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted. Business Client No fix yet Fix from $1,9502018-03-14