Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2017-9613
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web …
Successfactors
No fix yet
CRITICAL 9.6
CVE-2016-6256EPSS 8%
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell…
Business One
No fix yet
HIGH 8.8
CVE-2017-8913
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks…
Netweaver Application Server Java
Mitigation only
HIGH 8.3
CVE-2017-8914
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user …
Hana Xs
Mitigation only
HIGH 7.5
CVE-2017-8915
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing …
Hana Xs
Mitigation only
HIGH 7.8
CVE-2017-8852
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted r…
Sapcar
No fix yet
HIGH 8.8
CVE-2017-7717
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users…
Netweaver Application Server Java
Mitigation only
HIGH 7.5
CVE-2017-7696EPSS 36%
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in t…
Sso Authentication Library
Mitigation only
CRITICAL 9.8
CVE-2016-6818
SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify…
Business Intelligence Platform
Mitigation only
CRITICAL 9.8
CVE-2016-6143
SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.
Hana
Mitigation only
CRITICAL 9.8
CVE-2017-7691
A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.
Trex
Mitigation only
CRITICAL 9.8
CVE-2016-10311
Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to t…
Netweaver
Mitigation only
MEDIUM 6.5
CVE-2016-10304
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and ser…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2017-6950
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, a…
Gui For Windows
Mitigation only
HIGH 7.5
CVE-2017-5997
The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash…
Sap Kernel
Mitigation only
HIGH 7.5
CVE-2017-5372
The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system informati…
Netweaver
No fix yet
HIGH 7.5
CVE-2016-10005
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~t…
Solution Manager
No fix yet
MEDIUM 6.5
CVE-2016-9563 KEVEPSS 24%
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi…
Netweaver Application Server Java
Mitigation only
HIGH 7.5
CVE-2016-9562
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the …
Netweaver Application Server Java
Mitigation only
MEDIUM 6.5
CVE-2016-4407
The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to imperson…
Sapcryptolib
Mitigation only
HIGH 7.8
CVE-2016-3946
SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note …
Sapconsole
Mitigation only
MEDIUM 5.5
CVE-2016-3638
SAP SLD Registration Program (aka SLDREG) allows local users to cause a denial of service (memory corruption and process termination) via a crafted H…
Sld Registration
No fix yet
HIGH 7.5
CVE-2016-3635
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remot…
Netweaver
Mitigation only
CRITICAL 9.1
CVE-2016-7435
The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.…
Netweaver
Mitigation only
HIGH 7.5
CVE-2016-4551
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to …
Netweaver
Mitigation only
MEDIUM 5.3
CVE-2016-6146
The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security No…
Trex
No fix yet
CRITICAL 9.8
CVE-2016-6137
An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security N…
Trex
No fix yet
HIGH 7.5
CVE-2016-6142
SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to th…
Hana
No fix yet
MEDIUM 5.8
CVE-2016-5847
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted…
Sapcar Archive Tool
No fix yet
MEDIUM 5.5
CVE-2016-5845
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (prog…
Sapcar
No fix yet