Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Adaptive Server Enterprise MEDIUM 6.5
CVE-2020-6259

Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information which would otherwise be restr…

Mitigation only
Fix from $1,600 2020-05-12
Enterprise Threat Detection MEDIUM 6.1
CVE-2020-6254

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflect…

Mitigation only
Fix from $1,600 2020-05-12
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2020-6257

SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cros…

Mitigation only
Fix from $1,600 2020-05-12
Businessobjects Business Intelligence Platform CRITICAL 9.8
CVE-2020-6242

SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central…

Mitigation only
Fix from $2,300 2020-05-12
Adaptive Server Enterprise HIGH 8.8
CVE-2020-6241

SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the …

Mitigation only
Fix from $1,950 2020-05-12
Adaptive Server Enterprise HIGH 8.8
CVE-2020-6243

Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks …

Mitigation only
Fix from $1,950 2020-05-12
Business Client HIGH 7.8
CVE-2020-6244

SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted…

Mitigation only
Fix from $1,950 2020-05-12
Netweaver Application Server Abap HIGH 7.5
CVE-2020-6240

SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacke…

Mitigation only
Fix from $1,950 2020-05-12
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6213

SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulne…

Mitigation only
Fix from $1,600 2020-04-24
Erp MEDIUM 5.4
CVE-2020-6212

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and…

Mitigation only
Fix from $1,600 2020-04-24
Businessobjects Business Intelligence Platform CRITICAL 9.8
CVE-2020-6195

SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclos…

Mitigation only
Fix from $2,300 2020-04-14
Netweaver Knowledge Management And Collaboration \(kmc Cm\) HIGH 8.8
CVE-2020-6225

SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not suffi…

Mitigation only
Fix from $1,950 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2020-6211

SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to …

Mitigation only
Fix from $1,600 2020-04-14
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6215

SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker…

No fix yet
Fix from $1,600 2020-04-14
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6217

SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficien…

Mitigation only
Fix from $1,600 2020-04-14
Commerce Cloud CRITICAL 9.3
CVE-2020-6238

SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing …

Mitigation only
Fix from $2,300 2020-04-14
Solution Manager HIGH 8.6
CVE-2020-6235

SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, …

Mitigation only
Fix from $1,950 2020-04-14
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2020-6237

Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to acce…

Mitigation only
Fix from $1,950 2020-04-14
Host Agent HIGH 7.2
CVE-2020-6234

SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying ope…

No fix yet
Fix from $1,950 2020-04-14
Adaptive Extensions HIGH 7.2
CVE-2020-6236

SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership a…

Mitigation only
Fix from $1,950 2020-04-14
Commerce Cloud MEDIUM 5.3
CVE-2020-6232

SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This af…

Mitigation only
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2020-6219

SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allo…

Mitigation only
Fix from $1,950 2020-04-14
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2020-6227

SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to s…

Mitigation only
Fix from $1,950 2020-04-14
Business Client HIGH 7.5
CVE-2020-6228

SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions …

Mitigation only
Fix from $1,950 2020-04-14
Orientdb HIGH 7.2
CVE-2020-6230

SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the applicat…

Mitigation only
Fix from $1,950 2020-04-14
Netweaver Application Server Java MEDIUM 6.2
CVE-2020-6224

SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access u…

Mitigation only
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2020-6216

SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in re…

Mitigation only
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 6.1
CVE-2020-6223

The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to incl…

Mitigation only
Fix from $1,600 2020-04-14
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6229

SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75…

Mitigation only
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2020-6221

Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controll…

Mitigation only
Fix from $1,600 2020-04-14