Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2018-2371
The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in C…
Netweaver Java Web Application
Mitigation only
MEDIUM 5.3
CVE-2018-2369
Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attac…
Hana
Mitigation only
MEDIUM 5.3
CVE-2018-2370
Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, …
Bi Launchpad
Mitigation only
HIGH 8.8
CVE-2018-2361
In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required…
Solution Manager
Mitigation only
HIGH 7.5
CVE-2018-2360
SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause con…
Sap Kernel
Mitigation only
MEDIUM 5.3
CVE-2018-2362
A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose informa…
Hana
Mitigation only
CRITICAL 9.8
CVE-2017-16684
SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti…
Business Intelligence Promotion Management Application
Mitigation only
HIGH 8.8
CVE-2017-16689
A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f…
Sap Kernel
Mitigation only
HIGH 7.8
CVE-2017-16690
A malicious DLL preload attack possible on NwSapSetup and Installation self-extracting program for SAP Plant Connectivity 2.3 and 15.0. It is possibl…
Plant Connectivity
Mitigation only
HIGH 7.5
CVE-2017-16680
Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller servic…
Hana Extended Application Services
Mitigation only
MEDIUM 6.5
CVE-2017-16683
Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from acc…
Businessobjects
Mitigation only
MEDIUM 6.5
CVE-2017-16691
SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note…
Business Application Software Integrated Solution
Mitigation only
MEDIUM 6.1
CVE-2017-16679
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21…
Sap Kernel
Mitigation only
MEDIUM 6.1
CVE-2017-16681
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controll…
Business Intelligence Promotion Management Application
Mitigation only
MEDIUM 6.1
CVE-2017-16685
Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient…
Business Warehouse Universal Data Integration
Mitigation only
MEDIUM 5.3
CVE-2017-16687
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,…
Hana Database
Mitigation only
MEDIUM 6.1
CVE-2017-14516
Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292.
Businessobjects Financial Consolidation
Mitigation only
CRITICAL 9.8
CVE-2017-15295
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
Point Of Sale Xpress Server
Mitigation only
HIGH 8.8
CVE-2017-15296
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
Customer Relationship Management
No fix yet
HIGH 7.5
CVE-2017-15297
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
Host Agent
Mitigation only
CRITICAL 9.8
CVE-2017-15293
Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at…
Point Of Sale Xpress Server
Mitigation only
MEDIUM 6.1
CVE-2017-15294
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
Customer Relationship Management
Mitigation only
HIGH 7.5
CVE-2017-14511
An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/…
E Recruiting
Mitigation only
HIGH 7.5
CVE-2017-12637 KEVEPSS 95%
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2017-11459
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr…
Trex
Mitigation only
MEDIUM 6.5
CVE-2017-11457
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2017-11458
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2017-11460
Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary …
Netweaver Portal
Mitigation only
HIGH 7.5
CVE-2017-9844EPSS 6%
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java…
Netweaver
Mitigation only
HIGH 7.5
CVE-2017-9845
disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG reque…
Netweaver
Mitigation only