Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver CRITICAL 9.8
CVE-2013-1592EPSS 24%

A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Serv…

No fix yet
Fix from $2,300 2020-01-23
Netweaver Internet Communication Manager \(kernel\) HIGH 7.5
CVE-2020-6304

Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL6…

Mitigation only
Fix from $1,950 2020-01-14
Process Integration MEDIUM 6.1
CVE-2020-6305

PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, result…

Mitigation only
Fix from $1,600 2020-01-14
Disclosure Management MEDIUM 5.4
CVE-2020-6303

SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.

Fix: 10.1+
Fix from $1,600 2020-01-14
Enterprise Extension Financial Services HIGH 8.8
CVE-2019-0383

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…

Mitigation only
Fix from $1,950 2019-12-17
Enterprise Extension Financial Services HIGH 8.8
CVE-2019-0384

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.…

Mitigation only
Fix from $1,950 2019-12-17
Enable Now HIGH 7.5
CVE-2019-0404

SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.

Fix: 1911+
Fix from $1,950 2019-12-11
Enable Now HIGH 7.5
CVE-2019-0405

SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leadi…

Fix: 1911+
Fix from $1,950 2019-12-11
Enable Now CRITICAL 9.8
CVE-2019-0403

SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Comm…

Fix: 1911+
Fix from $2,300 2019-12-11
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2019-0398

Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, m…

Mitigation only
Fix from $1,950 2019-12-11
Portfolio And Project Management MEDIUM 6.5
CVE-2019-0399

SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user …

Mitigation only
Fix from $1,600 2019-12-11
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0395

SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori…

Fix: 4.2+
Fix from $1,600 2019-12-11
Businessobjects Business Intelligence Platform HIGH 7.1
CVE-2019-0396

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently valida…

Mitigation only
Fix from $1,950 2019-11-13
Erp Sales MEDIUM 6.3
CVE-2019-0386

Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1…

Mitigation only
Fix from $1,600 2019-11-13
Ui MEDIUM 5.3
CVE-2019-0388

SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content d…

Mitigation only
Fix from $1,600 2019-11-13
Netweaver Application Server Java HIGH 8.8
CVE-2019-0389

An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privile…

Mitigation only
Fix from $1,950 2019-11-13
Enable Now MEDIUM 6.5
CVE-2019-0385

SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Fix: 1908+
Fix from $1,600 2019-11-13
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0382

A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corre…

Fix: 4.2+
Fix from $1,600 2019-11-13
Hana Database HIGH 7.5
CVE-2019-0350

SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP…

Mitigation only
Fix from $1,950 2019-11-04
Financial Consolidation MEDIUM 6.5
CVE-2019-0370

Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere wi…

Mitigation only
Fix from $1,600 2019-10-08
Dynamic Tier MEDIUM 5.5
CVE-2019-0381

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can resul…

Mitigation only
Fix from $1,600 2019-10-08
Financial Consolidation MEDIUM 5.4
CVE-2019-0369

SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute …

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0374

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0375

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0376

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0377

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controll…

Mitigation only
Fix from $1,600 2019-10-08
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2019-0378

SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlle…

Mitigation only
Fix from $1,600 2019-10-08
Process Integration MEDIUM 5.3
CVE-2019-0379

SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security pro…

Mitigation only
Fix from $1,600 2019-10-08
Customer Relationship Management Bbpcrm MEDIUM 5.4
CVE-2019-0368

SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does…

Mitigation only
Fix from $1,600 2019-10-08
Sap Kernel HIGH 7.5
CVE-2019-0365

SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22…

Mitigation only
Fix from $1,950 2019-09-10