Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver Application Server Abap HIGH 7.6
CVE-2020-26832

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and S…

No fix yet
Fix from $1,950 2020-12-09
Netweaver Application Server Abap MEDIUM 6.1
CVE-2020-26835

SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java sc…

Mitigation only
Fix from $1,600 2020-12-09
Solution Manager MEDIUM 6.1
CVE-2020-26836

SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability,…

No fix yet
Fix from $1,600 2020-12-09
Hana Database MEDIUM 5.4
CVE-2020-26834

SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possibl…

Mitigation only
Fix from $1,600 2020-12-09
Netweaver Application Server Java MEDIUM 6.5
CVE-2020-26826

Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) …

Mitigation only
Fix from $1,600 2020-12-09
Disclosure Management MEDIUM 6.4
CVE-2020-26828

SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some f…

Mitigation only
Fix from $1,600 2020-12-09
Fiori Launchpad \(news Tile Application\) MEDIUM 6.1
CVE-2020-26825

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile…

Mitigation only
Fix from $1,600 2020-11-13
Solution Manager CRITICAL 10.0
CVE-2020-26821

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26822

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26823

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Solution Manager CRITICAL 10.0
CVE-2020-26824

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization check…

Mitigation only
Fix from $2,300 2020-11-10
Netweaver Application Server Abap HIGH 8.8
CVE-2020-26819

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone…

Mitigation only
Fix from $1,950 2020-11-10
Netweaver Application Server Java HIGH 7.2
CVE-2020-26820

SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator …

No fix yet
Fix from $1,950 2020-11-10
Netweaver Application Server Abap HIGH 8.8
CVE-2020-26818

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro compone…

Mitigation only
Fix from $1,950 2020-11-10
Fiori Launchpad \(news Tile Application\) HIGH 8.6
CVE-2020-26815

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulne…

Mitigation only
Fix from $1,950 2020-11-10
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-26817

SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing …

Mitigation only
Fix from $1,950 2020-11-10
Commerce Cloud \(accelerator Payment Mock\) HIGH 7.5
CVE-2020-26810

SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…

Mitigation only
Fix from $1,950 2020-11-10
Sap As Abap\(dmis\) HIGH 7.2
CVE-2020-26808

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), version…

No fix yet
Fix from $1,950 2020-11-10
Commerce Cloud MEDIUM 5.3
CVE-2020-26809

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpo…

No fix yet
Fix from $1,600 2020-11-10
Commerce Cloud \(accelerator Payment Mock\) MEDIUM 5.3
CVE-2020-26811

SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over…

No fix yet
Fix from $1,600 2020-11-10
Banking Services MEDIUM 6.5
CVE-2020-6362

SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with othe…

Mitigation only
Fix from $1,600 2020-10-20
Netweaver Compare Systems MEDIUM 6.5
CVE-2020-6366

SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administra…

Mitigation only
Fix from $1,600 2020-10-20
Netweaver Composite Application Framework MEDIUM 6.1
CVE-2020-6367

There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An…

Mitigation only
Fix from $1,600 2020-10-20
Focused Run MEDIUM 5.9
CVE-2020-6369

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to byp…

No fix yet
Fix from $1,600 2020-10-20
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6315

SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive…

Mitigation only
Fix from $1,600 2020-10-20
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6308EPSS 62%

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary va…

Mitigation only
Fix from $1,600 2020-10-20
Netweaver Application Server Java MEDIUM 6.1
CVE-2020-6365

SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to…

Mitigation only
Fix from $1,600 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6372

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6373

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,950 2020-10-15
3d Visual Enterprise Viewer HIGH 7.8
CVE-2020-6374

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which …

Mitigation only
Fix from $1,950 2020-10-15