Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2018-2371 The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in C… Netweaver Java Web Application Mitigation only Fix from $1,6002018-02-14 MEDIUM 5.3 CVE-2018-2369 Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attac… Hana Mitigation only Fix from $1,6002018-02-14 MEDIUM 5.3 CVE-2018-2370 Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, … Bi Launchpad Mitigation only Fix from $1,6002018-02-14 HIGH 8.8 CVE-2018-2361 In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required… Solution Manager Mitigation only Fix from $1,9502018-01-09 HIGH 7.5 CVE-2018-2360 SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause con… Sap Kernel Mitigation only Fix from $1,9502018-01-09 MEDIUM 5.3 CVE-2018-2362 A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose informa… Hana Mitigation only Fix from $1,6002018-01-09 CRITICAL 9.8 CVE-2017-16684 SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti… Business Intelligence Promotion Management Application Mitigation only Fix from $2,3002017-12-12 HIGH 8.8 CVE-2017-16689 A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f… Sap Kernel Mitigation only Fix from $1,9502017-12-12 HIGH 7.8 CVE-2017-16690 A malicious DLL preload attack possible on NwSapSetup and Installation self-extracting program for SAP Plant Connectivity 2.3 and 15.0. It is possibl… Plant Connectivity Mitigation only Fix from $1,9502017-12-12 HIGH 7.5 CVE-2017-16680 Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller servic… Hana Extended Application Services Mitigation only Fix from $1,9502017-12-12 MEDIUM 6.5 CVE-2017-16683 Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from acc… Businessobjects Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.5 CVE-2017-16691 SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note… Business Application Software Integrated Solution Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-16679 URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21… Sap Kernel Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-16681 Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controll… Business Intelligence Promotion Management Application Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-16685 Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient… Business Warehouse Universal Data Integration Mitigation only Fix from $1,6002017-12-12 MEDIUM 5.3 CVE-2017-16687 The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,… Hana Database Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-14516 Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292. Businessobjects Financial Consolidation Mitigation only Fix from $1,6002017-12-03 CRITICAL 9.8 CVE-2017-15295 Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064. Point Of Sale Xpress Server Mitigation only Fix from $2,3002017-10-16 HIGH 8.8 CVE-2017-15296 The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. Customer Relationship Management No fix yet Fix from $1,9502017-10-16 HIGH 7.5 CVE-2017-15297 SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993. Host Agent Mitigation only Fix from $1,9502017-10-16 CRITICAL 9.8 CVE-2017-15293 Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at… Point Of Sale Xpress Server Mitigation only Fix from $2,3002017-10-16 MEDIUM 6.1 CVE-2017-15294 The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964. Customer Relationship Management Mitigation only Fix from $1,6002017-10-16 HIGH 7.5 CVE-2017-14511 An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/… E Recruiting Mitigation only Fix from $1,9502017-09-17 HIGH 7.5 CVE-2017-12637 KEVEPSS 95% Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a… Netweaver Application Server Java Mitigation only Fix from $1,9502017-08-07 CRITICAL 9.8 CVE-2017-11459 SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr… Trex Mitigation only Fix from $2,3002017-07-25 MEDIUM 6.5 CVE-2017-11457 XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o… Netweaver Application Server Java Mitigation only Fix from $1,6002017-07-25 MEDIUM 6.1 CVE-2017-11458 Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary… Netweaver Application Server Java Mitigation only Fix from $1,6002017-07-25 MEDIUM 6.1 CVE-2017-11460 Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary … Netweaver Portal Mitigation only Fix from $1,6002017-07-25 HIGH 7.5 CVE-2017-9844EPSS 6% SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java… Netweaver Mitigation only Fix from $1,9502017-07-12 HIGH 7.5 CVE-2017-9845 disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG reque… Netweaver Mitigation only Fix from $1,9502017-07-12