Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2014-8592
Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process ter…
Netweaver
Mitigation only
MEDIUM 6.0
CVE-2014-8313
Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via uns…
Hana
No fix yet
MEDIUM 5.0
CVE-2014-8315
polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allow…
Businessobjects Explorer
Mitigation only
MEDIUM 5.0
CVE-2014-8316
XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrar…
Businessobjects Explorer
No fix yet
HIGH 7.1
CVE-2014-8310
The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFact…
Businessobjects
No fix yet
MEDIUM 5.0
CVE-2014-8309
SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depen…
Businessobjects
Mitigation only
MEDIUM 6.5
CVE-2014-6252
Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated …
Netweaver
Mitigation only
MEDIUM 6.8
CVE-2014-5505
Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file.
Crystal Reports
Mitigation only
MEDIUM 6.8
CVE-2014-5506
Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT fil…
Crystal Reports
Mitigation only
HIGH 7.5
CVE-2014-5175
The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a ve…
Solution Manager
Mitigation only
MEDIUM 6.0
CVE-2014-5176
SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors.
Fi Manager Self Service
No fix yet
MEDIUM 5.0
CVE-2014-5173
SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that w…
Hana Extended Application Services
No fix yet
MEDIUM 5.8
CVE-2014-4159
Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbit…
Supplier Relationship Management
No fix yet
MEDIUM 5.0
CVE-2014-4005
SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Brazil
Mitigation only
MEDIUM 5.0
CVE-2014-4006
The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain ac…
Oil Industry Solution Traders And Schedulers Workbench
Mitigation only
MEDIUM 5.0
CVE-2014-4007
The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Upgrade Tools
Mitigation only
MEDIUM 5.0
CVE-2014-4008
SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Web Services Tool
Mitigation only
MEDIUM 5.0
CVE-2014-4009
SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Computing Center Management System Monitoring
Mitigation only
MEDIUM 5.0
CVE-2014-4010
SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Transaction Data Pool
No fix yet
MEDIUM 5.0
CVE-2014-4011
SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Capacity Leveling
No fix yet
MEDIUM 5.0
CVE-2014-4012
SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Open Hub Service
Mitigation only
HIGH 7.5
CVE-2014-4003
The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system.
Netweaver
No fix yet
MEDIUM 5.0
CVE-2014-4004
The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote …
Project System
No fix yet
MEDIUM 5.0
CVE-2014-3129
The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted …
Netweaver Software Lifecycle Manager
Mitigation only
MEDIUM 5.0
CVE-2014-3133
SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o…
Netweaver Java Application Server
Mitigation only
HIGH 7.5
CVE-2014-2751
SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Print And Output Management
Mitigation only
HIGH 7.5
CVE-2014-2752
SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via u…
Business Object Processing Framework For Abap
Mitigation only
HIGH 7.5
CVE-2013-7362
An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.
Ccms Agent
No fix yet
HIGH 7.5
CVE-2013-7363
Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the …
Solution Manager
Mitigation only
HIGH 7.5
CVE-2013-7364
An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri…
Netweaver
Mitigation only