Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web Dynpro Abap MEDIUM 6.1
CVE-2021-21478

SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.

Mitigation only
Fix from $1,600 2021-02-09
Netweaver Master Data Management HIGH 7.5
CVE-2021-21469

When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an e…

Mitigation only
Fix from $1,950 2021-01-12
Business Warehouse MEDIUM 6.5
CVE-2021-21468

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allow…

No fix yet
Fix from $1,600 2021-01-12
Cla Assistant MEDIUM 6.5
CVE-2021-21471

In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints which are not intended to be…

Fix: 2.8.5+
Fix from $1,600 2021-01-12
Business Warehouse CRITICAL 9.9
CVE-2021-21465

The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker …

No fix yet
Fix from $2,300 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21453

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21454

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21455

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21456

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21457

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21458

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21459

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21460

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21461

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21462

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21463

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
Business Warehouse HIGH 8.8
CVE-2021-21466

SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to …

No fix yet
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21449

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21450

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21451

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SGI file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
3d Visual Enterprise Viewer HIGH 8.8
CVE-2021-21452

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2021-01-12
Netweaver Application Server Abap HIGH 7.5
CVE-2021-21446

SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a se…

Mitigation only
Fix from $1,950 2021-01-12
Graphical User Interface MEDIUM 6.5
CVE-2021-21448

SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend systems in the client PCs memo…

Mitigation only
Fix from $1,600 2021-01-12
Commerce Cloud MEDIUM 5.4
CVE-2021-21445

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Conten…

Mitigation only
Fix from $1,600 2021-01-12
Businessobjects Business Intelligence MEDIUM 5.4
CVE-2021-21447

SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into t…

Mitigation only
Fix from $1,600 2021-01-12
Netweaver Application Server Java CRITICAL 10.0
CVE-2020-26829

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because…

Mitigation only
Fix from $2,300 2020-12-09
Businessobjects Business Intelligence Platform CRITICAL 9.6
CVE-2020-26831

SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal repor…

Mitigation only
Fix from $2,300 2020-12-09
Solution Manager CRITICAL 9.1
CVE-2020-26837

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an e…

No fix yet
Fix from $2,300 2020-12-09
Business Warehouse CRITICAL 9.1
CVE-2020-26838

SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacke…

Mitigation only
Fix from $2,300 2020-12-09
Solution Manager HIGH 8.1
CVE-2020-26830

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due …

No fix yet
Fix from $1,950 2020-12-09