Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2014-8592 Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process ter… Netweaver Mitigation only Fix from $1,6002014-11-04 MEDIUM 6.0 CVE-2014-8313 Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via uns… Hana No fix yet Fix from $1,6002014-10-16 MEDIUM 5.0 CVE-2014-8315 polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allow… Businessobjects Explorer Mitigation only Fix from $1,6002014-10-16 MEDIUM 5.0 CVE-2014-8316 XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrar… Businessobjects Explorer No fix yet Fix from $1,6002014-10-16 HIGH 7.1 CVE-2014-8310 The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFact… Businessobjects No fix yet Fix from $1,9502014-10-16 MEDIUM 5.0 CVE-2014-8309 SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depen… Businessobjects Mitigation only Fix from $1,6002014-10-16 MEDIUM 6.5 CVE-2014-6252 Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated … Netweaver Mitigation only Fix from $1,6002014-09-05 MEDIUM 6.8 CVE-2014-5505 Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file. Crystal Reports Mitigation only Fix from $1,6002014-09-04 MEDIUM 6.8 CVE-2014-5506 Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT fil… Crystal Reports Mitigation only Fix from $1,6002014-09-04 HIGH 7.5 CVE-2014-5175 The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a ve… Solution Manager Mitigation only Fix from $1,9502014-07-31 MEDIUM 6.0 CVE-2014-5176 SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors. Fi Manager Self Service No fix yet Fix from $1,6002014-07-31 MEDIUM 5.0 CVE-2014-5173 SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that w… Hana Extended Application Services No fix yet Fix from $1,6002014-07-31 MEDIUM 5.8 CVE-2014-4159 Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbit… Supplier Relationship Management No fix yet Fix from $1,6002014-06-13 MEDIUM 5.0 CVE-2014-4005 SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Brazil Mitigation only Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-4006 The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain ac… Oil Industry Solution Traders And Schedulers Workbench Mitigation only Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-4007 The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Upgrade Tools Mitigation only Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-4008 SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Web Services Tool Mitigation only Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-4009 SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Computing Center Management System Monitoring Mitigation only Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-4010 SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Transaction Data Pool No fix yet Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-4011 SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Capacity Leveling No fix yet Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-4012 SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Open Hub Service Mitigation only Fix from $1,6002014-06-09 HIGH 7.5 CVE-2014-4003 The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system. Netweaver No fix yet Fix from $1,9502014-06-09 MEDIUM 5.0 CVE-2014-4004 The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote … Project System No fix yet Fix from $1,6002014-06-09 MEDIUM 5.0 CVE-2014-3129 The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted … Netweaver Software Lifecycle Manager Mitigation only Fix from $1,6002014-04-30 MEDIUM 5.0 CVE-2014-3133 SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o… Netweaver Java Application Server Mitigation only Fix from $1,6002014-04-30 HIGH 7.5 CVE-2014-2751 SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Print And Output Management Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2014-2752 SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via u… Business Object Processing Framework For Abap Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7362 An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors. Ccms Agent No fix yet Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7363 Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the … Solution Manager Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7364 An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri… Netweaver Mitigation only Fix from $1,9502014-04-10