Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2022-41272 An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver P… Netweaver Process Integration Mitigation only Fix from $1,9502022-12-13 CRITICAL 9.4 CVE-2022-41271 An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - vers… Netweaver Process Integration Mitigation only Fix from $2,3002022-12-13 HIGH 8.8 CVE-2022-41264 Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allow… Basis Mitigation only Fix from $1,9502022-12-13 HIGH 8.8 CVE-2022-41267 SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objec… Business Objects Business Intelligence Platform Mitigation only Fix from $1,9502022-12-13 HIGH 7.5 CVE-2022-41268 In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CP… Business Planning And Consolidation No fix yet Fix from $1,9502022-12-13 MEDIUM 6.1 CVE-2022-41266 Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs … Commerce Webservices 2.0 Mitigation only Fix from $1,6002022-12-13 MEDIUM 6.1 CVE-2022-41262 Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a sc… Netweaver Application Server Java Mitigation only Fix from $1,6002022-12-12 MEDIUM 5.5 CVE-2022-41261 SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data… Solution Manager Mitigation only Fix from $1,6002022-12-12 MEDIUM 6.0 CVE-2022-31596 Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Busi… Business Objects Business Intelligence Platform Mitigation only Fix from $1,6002022-12-12 MEDIUM 6.1 CVE-2022-41260 SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject … Financial Consolidation Mitigation only Fix from $1,6002022-11-08 HIGH 8.7 CVE-2022-41214 Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges to use a … Netweaver Application Server Abap Mitigation only Fix from $1,9502022-11-08 MEDIUM 6.5 CVE-2022-41258 Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when ru… Financial Consolidation Mitigation only Fix from $1,6002022-11-08 MEDIUM 6.5 CVE-2022-41259 SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashi… Sql Anywhere Mitigation only Fix from $1,6002022-11-08 HIGH 7.8 CVE-2022-41211 Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and … 3d Visual Enterprise Author Mitigation only Fix from $1,9502022-11-08 MEDIUM 5.4 CVE-2022-41208 Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter curr… Financial Consolidation Mitigation only Fix from $1,6002022-11-08 HIGH 8.8 CVE-2022-41203 In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated attacker with low privileges can … Businessobjects Business Intelligence Mitigation only Fix from $1,9502022-11-08 MEDIUM 6.1 CVE-2022-41205 SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registr… Gui Mitigation only Fix from $1,6002022-11-08 MEDIUM 6.1 CVE-2022-41207 SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsens… Biller Direct No fix yet Fix from $1,6002022-11-08 HIGH 8.8 CVE-2022-41204 An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject … Commerce Mitigation only Fix from $1,9502022-10-11 MEDIUM 5.4 CVE-2022-41206 SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled … Businessobjects Business Intelligence Mitigation only Fix from $1,6002022-10-11 MEDIUM 5.2 CVE-2022-41209 SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patte… Customer Data Cloud Mitigation only Fix from $1,6002022-10-11 MEDIUM 5.2 CVE-2022-41210 SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attac… Customer Data Cloud Mitigation only Fix from $1,6002022-10-11 HIGH 7.8 CVE-2022-41184 Due to lack of proper memory management, when a victim opens a manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources i… 3d Visual Enterprise Author Mitigation only Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-41185 Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, MataiPersistence.dll) file received from untru… 3d Visual Enterprise Author Mitigation only Fix from $1,9502022-10-11 MEDIUM 5.5 CVE-2022-41183 Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file received from untrusted sources in … 3d Visual Enterprise Author Mitigation only Fix from $1,6002022-10-11 HIGH 7.8 CVE-2022-41179 Due to lack of proper memory management, when a victim opens a manipulated Jupiter Tesselation (.jt, JtTranslator.exe) file received from untrusted s… 3d Visual Enterprise Author Mitigation only Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-41180 Due to lack of proper memory management, when a victim opens a manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untr… 3d Visual Enterprise Author Mitigation only Fix from $1,9502022-10-11 MEDIUM 5.5 CVE-2022-41178 Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTranslator.exe) file received fr… 3d Visual Enterprise Author Mitigation only Fix from $1,6002022-10-11 MEDIUM 5.5 CVE-2022-41181 Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.dll) file received from untrus… 3d Visual Enterprise Author Mitigation only Fix from $1,6002022-10-11 MEDIUM 5.5 CVE-2022-41182 Due to lack of proper memory management, when a victim opens manipulated Parasolid Part and Assembly (.x_b, CoreCadTranslator.exe) file received from… 3d Visual Enterprise Author Mitigation only Fix from $1,6002022-10-11