Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Commerce CRITICAL 9.9
CVE-2021-27602

SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are transl…

Mitigation only
Fix from $2,300 2021-04-13
Netweaver Application Server Abap MEDIUM 6.5
CVE-2021-27603

An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length …

Mitigation only
Fix from $1,600 2021-04-13
Focused Run MEDIUM 6.5
CVE-2021-27609

SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData s…

Mitigation only
Fix from $1,600 2021-04-13
Manufacturing Execution MEDIUM 5.4
CVE-2021-27600

SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parame…

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Application Server Java MEDIUM 5.4
CVE-2021-27601

SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a…

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Application Server Java MEDIUM 5.3
CVE-2021-27598

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ…

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Master Data Management HIGH 8.3
CVE-2021-21482

SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the …

Mitigation only
Fix from $1,950 2021-04-13
Netweaver Application Server Java MEDIUM 6.5
CVE-2021-21485

An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow …

Mitigation only
Fix from $1,600 2021-04-13
Netweaver Application Server Java MEDIUM 6.1
CVE-2021-21491

SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attack…

Mitigation only
Fix from $1,600 2021-03-10
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27585

When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer versi…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27586

When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version …

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27587

When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, t…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27588

When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27589

When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27590

When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27591

When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…

Mitigation only
Fix from $1,950 2021-03-09
3d Visual Enterprise Viewer HIGH 7.8
CVE-2021-27592

When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes a…

Mitigation only
Fix from $1,950 2021-03-09
Payment Engine HIGH 8.8
CVE-2021-21487

SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Mitigation only
Fix from $1,950 2021-03-09
Netweaver Knowledge Management MEDIUM 6.5
CVE-2021-21488

Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w…

Mitigation only
Fix from $1,600 2021-03-09
Hana CRITICAL 9.8
CVE-2021-21484

LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi…

Mitigation only
Fix from $2,300 2021-03-09
Manufacturing Integration And Intelligence HIGH 8.8
CVE-2021-21480EPSS 51%

SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a r…

No fix yet
Fix from $1,950 2021-03-09
Netweaver HIGH 8.8
CVE-2021-21481

The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This…

Mitigation only
Fix from $1,950 2021-03-09
Enterprise Financial Services HIGH 8.8
CVE-2021-21486

SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz…

Mitigation only
Fix from $1,950 2021-03-09
Commerce CRITICAL 9.9
CVE-2021-21477EPSS 30%

SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attack…

Mitigation only
Fix from $2,300 2021-02-09
Scimono CRITICAL 9.1
CVE-2021-21479EPSS 10%

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the sys…

Fix: 0.0.19+
Fix from $2,300 2021-02-09
Software Provisioning Manager HIGH 8.8
CVE-2021-21472

SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installati…

Mitigation only
Fix from $1,950 2021-02-09
Netweaver Master Data Management Server HIGH 7.5
CVE-2021-21475

Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation …

Mitigation only
Fix from $1,950 2021-02-09
Hana Database MEDIUM 6.5
CVE-2021-21474

SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion is…

Mitigation only
Fix from $1,600 2021-02-09
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2021-21444

SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be…

Mitigation only
Fix from $1,600 2021-02-09
Ui5 MEDIUM 6.1
CVE-2021-21476

SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a…

Fix: 1.38.49 / 1.52.49+
Fix from $1,600 2021-02-09