Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2020-6222

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlle…

Mitigation only
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2020-6226

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inpu…

Mitigation only
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2020-6231

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inpu…

Mitigation only
Fix from $1,600 2020-04-14
Businessobjects Business Intelligence Platform MEDIUM 5.0
CVE-2020-6218

Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information tha…

Mitigation only
Fix from $1,600 2020-04-14
Fiori Launchpad MEDIUM 6.1
CVE-2020-6210

SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag …

Mitigation only
Fix from $1,600 2020-03-10
Solution Manager CRITICAL 9.8
CVE-2020-6207 KEVEPSS 98%

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a servic…

Mitigation only
Fix from $2,300 2020-03-10
Netweaver CRITICAL 9.1
CVE-2020-6203

SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validat…

Mitigation only
Fix from $2,300 2020-03-10
Crystal Reports HIGH 8.2
CVE-2020-6208

SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code…

Mitigation only
Fix from $1,950 2020-03-10
Disclosure Management HIGH 7.5
CVE-2020-6209

SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration…

Mitigation only
Fix from $1,950 2020-03-10
Netweaver Application Server Java HIGH 7.2
CVE-2020-6202

SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate th…

Mitigation only
Fix from $1,950 2020-03-10
Commerce Cloud MEDIUM 6.1
CVE-2020-6201

The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain…

Mitigation only
Fix from $1,600 2020-03-10
Netweaver As Abap Business Server Pages MEDIUM 6.1
CVE-2020-6205

SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53…

Mitigation only
Fix from $1,600 2020-03-10
Erp MEDIUM 5.4
CVE-2020-6199

The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate…

Mitigation only
Fix from $1,600 2020-03-10
Commerce Cloud MEDIUM 5.4
CVE-2020-6200

The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross…

Mitigation only
Fix from $1,600 2020-03-10
Solution Manager CRITICAL 9.8
CVE-2020-6198

SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to contro…

Mitigation only
Fix from $2,300 2020-03-10
Businessobjects Mobile HIGH 7.5
CVE-2020-6196

SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which he can block all the threads…

Mitigation only
Fix from $1,950 2020-03-10
Enable Now MEDIUM 5.4
CVE-2020-6178

SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to…

Fix: 1911+
Fix from $1,600 2020-03-10
Erp HIGH 8.8
CVE-2020-6188

VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (…

Mitigation only
Fix from $1,950 2020-02-12
Host Agent HIGH 7.5
CVE-2020-6186

SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host…

Mitigation only
Fix from $1,950 2020-02-12
Landscape Management HIGH 7.2
CVE-2020-6191

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Age…

Mitigation only
Fix from $1,950 2020-02-12
Landscape Management HIGH 7.2
CVE-2020-6192

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent …

Mitigation only
Fix from $1,950 2020-02-12
Netweaver Knowledge Management MEDIUM 6.1
CVE-2020-6193

SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts le…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver Application Server Java MEDIUM 5.8
CVE-2020-6190

Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about th…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver MEDIUM 5.4
CVE-2020-6185

Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, …

Mitigation only
Fix from $1,600 2020-02-12
Businessobjects Business Intelligence Platform MEDIUM 5.3
CVE-2020-6189

Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise…

Mitigation only
Fix from $1,600 2020-02-12
Host Agent MEDIUM 6.5
CVE-2020-6183

SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPO…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver MEDIUM 6.1
CVE-2020-6184

Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53,…

Mitigation only
Fix from $1,600 2020-02-12
Abap Platform MEDIUM 5.8
CVE-2020-6181

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS ver…

Mitigation only
Fix from $1,600 2020-02-12
Netweaver CRITICAL 9.8
CVE-2011-1517

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafte…

Mitigation only
Fix from $2,300 2020-02-05
Netweaver HIGH 7.5
CVE-2013-1593

A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 S…

No fix yet
Fix from $1,950 2020-01-23