Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6375

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted …

Mitigation only
Fix from $1,600 2020-10-15
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2020-6376

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources wh…

Mitigation only
Fix from $1,600 2020-10-15
Introscope Enterprise Manager CRITICAL 10.0
CVE-2020-6364EPSS 6%

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a…

Mitigation only
Fix from $2,300 2020-10-15
Netweaver Application Server Java MEDIUM 6.1
CVE-2020-6319

SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScri…

Mitigation only
Fix from $1,600 2020-10-15
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2020-6323

SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an…

Mitigation only
Fix from $1,600 2020-10-15
Commerce Cloud MEDIUM 5.4
CVE-2020-6272

SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content …

Mitigation only
Fix from $1,600 2020-10-15
Business Planning And Consolidation MEDIUM 5.4
CVE-2020-6368

SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modif…

Mitigation only
Fix from $1,600 2020-10-15
Bank Analyzer MEDIUM 6.5
CVE-2020-6311

Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per…

Mitigation only
Fix from $1,600 2020-09-09
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6324

SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacke…

Mitigation only
Fix from $1,600 2020-09-09
Marketing HIGH 8.1
CVE-2020-6320

SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of …

Mitigation only
Fix from $1,950 2020-09-09
Abap Platform HIGH 7.2
CVE-2020-6318EPSS 6%

A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi…

No fix yet
Fix from $1,950 2020-09-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2020-6321

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of…

Mitigation only
Fix from $1,600 2020-09-09
Netweaver Knowledge Management MEDIUM 5.4
CVE-2020-6326

SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked…

Mitigation only
Fix from $1,600 2020-09-09
Commerce HIGH 8.1
CVE-2020-6302

SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacke…

Mitigation only
Fix from $1,950 2020-09-09
Netweaver Application Server Java MEDIUM 6.5
CVE-2020-6313

SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an…

Mitigation only
Fix from $1,600 2020-09-09
Fiori Launchpad MEDIUM 6.1
CVE-2020-6283

SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad ht…

Mitigation only
Fix from $1,600 2020-09-09
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2020-6312

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrati…

Mitigation only
Fix from $1,600 2020-09-09
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6288

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file…

Mitigation only
Fix from $1,600 2020-09-09
Businessobjects Business Intelligence Platform CRITICAL 9.1
CVE-2020-6294

Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun…

Mitigation only
Fix from $2,300 2020-08-12
Abap Platform HIGH 8.8
CVE-2020-6296

SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject co…

Mitigation only
Fix from $1,950 2020-08-12
Generic Market Data HIGH 8.1
CVE-2020-6298

SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Marke…

Mitigation only
Fix from $1,950 2020-08-12
Hcm Travel Management HIGH 8.1
CVE-2020-6301

SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify…

No fix yet
Fix from $1,950 2020-08-12
Adaptive Server Enterprise HIGH 7.8
CVE-2020-6295

Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat…

Mitigation only
Fix from $1,950 2020-08-12
Netweaver Application Server Java HIGH 7.5
CVE-2020-6309

SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authent…

Mitigation only
Fix from $1,950 2020-08-12
Netweaver Knowledge Management CRITICAL 9.0
CVE-2020-6284

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to ina…

Mitigation only
Fix from $2,300 2020-08-12
Netweaver Knowledge Management MEDIUM 6.5
CVE-2020-6293

SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to ac…

Mitigation only
Fix from $1,600 2020-08-12
Netweaver Application Server Java CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%

SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…

Mitigation only
Fix from $2,300 2020-07-14
Disclosure Management HIGH 8.8
CVE-2020-6289

SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to brow…

Mitigation only
Fix from $1,950 2020-07-14
Disclosure Management HIGH 8.8
CVE-2020-6291

SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating o…

Mitigation only
Fix from $1,950 2020-07-14
Disclosure Management HIGH 8.8
CVE-2020-6292

Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expirati…

Mitigation only
Fix from $1,950 2020-07-14