Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Businessobjects Edge HIGH 7.5
CVE-2015-2074

The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathn…

No fix yet
Fix from $1,950 2021-08-09
J2ee Engine MEDIUM 6.1
CVE-2018-17861

A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib …

No fix yet
Fix from $1,600 2021-08-09
J2ee Engine MEDIUM 6.1
CVE-2018-17862

A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc para…

No fix yet
Fix from $1,600 2021-08-09
J2ee Engine MEDIUM 6.1
CVE-2018-17865

A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter …

Mitigation only
Fix from $1,600 2021-08-09
Mobile Platform MEDIUM 5.5
CVE-2015-7731

SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security N…

Mitigation only
Fix from $1,600 2021-08-09
Lumira Server MEDIUM 5.4
CVE-2021-33682

SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This would …

Mitigation only
Fix from $1,600 2021-07-14
Netweaver Abap MEDIUM 5.3
CVE-2021-33684

SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.…

Mitigation only
Fix from $1,600 2021-07-14
Netweaver Guided Procedures HIGH 8.8
CVE-2021-33671

SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization che…

Mitigation only
Fix from $1,950 2021-07-14
Netweaver Application Server Java HIGH 7.5
CVE-2021-33670

SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to send multiple …

Patch available
Fix from $1,950 2021-07-14
Netweaver Abap HIGH 7.5
CVE-2021-33677

SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to inform…

Mitigation only
Fix from $1,950 2021-07-14
Customer Relationship Management HIGH 7.2
CVE-2021-33676

A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise c…

Mitigation only
Fix from $1,950 2021-07-14
Netweaver Application Server Abap MEDIUM 6.5
CVE-2021-33678

A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75…

No fix yet
Fix from $1,600 2021-07-14
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2021-33680

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow…

Mitigation only
Fix from $1,600 2021-07-14
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2021-33681

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds w…

Mitigation only
Fix from $1,600 2021-07-14
Netweaver Abap CRITICAL 9.8
CVE-2021-27610

SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about…

Mitigation only
Fix from $2,300 2021-06-16
Mobile Sdk Certificate Provider HIGH 7.8
CVE-2021-33669

Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For…

Fix: 3.0.8+
Fix from $1,950 2021-06-09
Commerce Cloud MEDIUM 6.1
CVE-2021-33666

When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver Application Server Abap MEDIUM 5.4
CVE-2021-33664

SAP NetWeaver Application Server ABAP (Applications based on Web Dynpro ABAP), versions - SAP_UI - 750,752,753,754,755, SAP_BASIS - 702, 731 does not…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver Application Server Abap MEDIUM 5.4
CVE-2021-33665

SAP NetWeaver Application Server ABAP (Applications based on SAP GUI for HTML), versions - KRNL64NUC - 7.49, KRNL64UC - 7.49,7.53, KERNEL - 7.49,7.53…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver Application Server Abap MEDIUM 5.3
CVE-2021-33663

SAP NetWeaver AS ABAP, versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Abap HIGH 7.5
CVE-2021-27629

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.2…

Mitigation only
Fix from $1,950 2021-06-09
Netweaver As Abap HIGH 7.5
CVE-2021-27630

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.2…

Mitigation only
Fix from $1,950 2021-06-09
Netweaver As Abap HIGH 7.5
CVE-2021-27631

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.2…

Mitigation only
Fix from $1,950 2021-06-09
Netweaver As Abap HIGH 7.5
CVE-2021-27632

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.2…

Mitigation only
Fix from $1,950 2021-06-09
Netweaver Abap HIGH 7.5
CVE-2021-27633

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7…

Mitigation only
Fix from $1,950 2021-06-09
Netweaver Application Server For Java MEDIUM 6.5
CVE-2021-27635

SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network an…

Patch available
Fix from $1,600 2021-06-09
Netweaver Abap MEDIUM 5.9
CVE-2021-27634

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7…

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27638

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of …

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27639

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of …

Mitigation only
Fix from $1,600 2021-06-09
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2021-27640

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2021-06-09