Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2018-2442
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session …
Businessobjects Business Intelligence
Mitigation only
MEDIUM 6.1
CVE-2018-2444
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script…
Businessobjects Financial Consolidation
Mitigation only
MEDIUM 5.5
CVE-2018-2441
Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unico…
Sap Kernel
No fix yet
HIGH 8.1
CVE-2017-16349
An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e…
Business Planning And Consolidation
Mitigation only
CRITICAL 9.1
CVE-2018-2437
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can l…
Internet Graphics Server
Mitigation only
HIGH 8.8
CVE-2018-2436
Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting i…
R\/3 Enterprise Retail
Mitigation only
HIGH 7.5
CVE-2018-2438
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prev…
Internet Graphics Server
Mitigation only
MEDIUM 5.9
CVE-2018-2439
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is valid…
Internet Graphics Server
Mitigation only
HIGH 7.5
CVE-2018-2433
SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.2…
Sap Kernel
Mitigation only
HIGH 7.5
CVE-2018-2424
SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to th…
Hana Database
Mitigation only
MEDIUM 5.5
CVE-2018-2425
Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be r…
Business One
Mitigation only
MEDIUM 5.3
CVE-2018-2428
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected a…
Infrastructure
Mitigation only
MEDIUM 6.1
CVE-2018-11415EPSS 8%
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indic…
Internet Transaction Server
No fix yet
HIGH 7.5
CVE-2018-2422
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…
Internet Graphics Server
Mitigation only
HIGH 7.5
CVE-2018-2423
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from access…
Internet Graphics Server
Mitigation only
CRITICAL 9.8
CVE-2018-2420
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi…
Internet Graphics Server
Mitigation only
HIGH 7.5
CVE-2018-2421
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…
Internet Graphics Server
Mitigation only
MEDIUM 5.4
CVE-2018-2416
SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
Identity Management
Mitigation only
MEDIUM 5.3
CVE-2018-2417
Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be re…
Identity Management
Mitigation only
CRITICAL 9.8
CVE-2018-2404
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
Disclosure Management
Mitigation only
HIGH 8.8
CVE-2018-2409
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some othe…
Cloud Platform
Mitigation only
HIGH 8.8
CVE-2018-2412
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Disclosure Management
Mitigation only
HIGH 8.8
CVE-2018-2413
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Disclosure Management
Mitigation only
HIGH 7.3
CVE-2018-2408
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password ch…
Businessobjects
Mitigation only
MEDIUM 6.5
CVE-2018-2403
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible…
Disclosure Management
Mitigation only
MEDIUM 5.4
CVE-2018-2405
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lea…
Solution Manager
Mitigation only
MEDIUM 5.4
CVE-2018-2410
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnera…
Business One
Mitigation only
MEDIUM 5.3
CVE-2018-2406
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup p…
Crystal Reports Server
Mitigation only
HIGH 8.4
CVE-2018-2402
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & r…
Hana
Mitigation only
HIGH 7.5
CVE-2018-2398
Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.
Business Client
No fix yet