Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hana Extended Application Services HIGH 7.1
CVE-2019-0363

Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server…

Fix: 1.0.118+
Fix from $1,950 2019-09-10
Hana MEDIUM 6.7
CVE-2019-0357

The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.

Mitigation only
Fix from $1,600 2019-09-10
Supplier Relationship Management MEDIUM 6.1
CVE-2019-0361

SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode us…

Mitigation only
Fix from $1,600 2019-09-10
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2019-0352

In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an…

Mitigation only
Fix from $1,950 2019-09-10
Netweaver Application Server Java HIGH 7.2
CVE-2019-0355

SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6…

Mitigation only
Fix from $1,950 2019-09-10
Advanced Business Application Programming Platform Kernel HIGH 7.2
CVE-2019-0349

SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.…

Mitigation only
Fix from $1,950 2019-08-14
Commerce Cloud CRITICAL 9.8
CVE-2019-0344 KEVEPSS 7%

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex…

Mitigation only
Fix from $2,300 2019-08-14
Netweaver Application Server Java CRITICAL 9.8
CVE-2019-0345

A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30…

Mitigation only
Fix from $2,300 2019-08-14
Enable Now HIGH 8.8
CVE-2019-0341

The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the a…

Mitigation only
Fix from $1,950 2019-08-14
Commerce Cloud HIGH 8.8
CVE-2019-0343

SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject …

Mitigation only
Fix from $1,950 2019-08-14
Netweaver HIGH 8.8
CVE-2019-0351

A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Becau…

Mitigation only
Fix from $1,950 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0346

Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0348

SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if th…

Mitigation only
Fix from $1,600 2019-08-14
Netweaver Process Integration MEDIUM 6.1
CVE-2019-0337

Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled in…

Mitigation only
Fix from $1,600 2019-08-14
Enable Now MEDIUM 5.4
CVE-2019-0340

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulner…

Fix: 1902+
Fix from $1,600 2019-08-14
Gateway MEDIUM 5.3
CVE-2019-0338

During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set,…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2019-0333

In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the at…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2019-0332

SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the se…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2019-0335

Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker …

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 5.4
CVE-2019-0334

When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malici…

Mitigation only
Fix from $1,600 2019-08-14
Businessobjects Business Intelligence MEDIUM 5.3
CVE-2019-0331

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, allows an attacker to access sen…

Mitigation only
Fix from $1,600 2019-08-14
Diagnostics Agent CRITICAL 9.1
CVE-2019-0330

The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to …

Mitigation only
Fix from $2,300 2019-07-10
Netweaver Application Server Java HIGH 7.2
CVE-2019-0327

SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.…

Mitigation only
Fix from $1,950 2019-07-10
Netweaver Process Integration HIGH 7.2
CVE-2019-0328

ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS c…

Mitigation only
Fix from $1,950 2019-07-10
Information Steward MEDIUM 6.1
CVE-2019-0329

SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Mitigation only
Fix from $1,600 2019-07-10
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2019-0326

SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not sufficiently encode user-controlled …

Mitigation only
Fix from $1,600 2019-07-10
Gateway HIGH 7.5
CVE-2019-0319

The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attac…

No fix yet
Fix from $1,950 2019-07-10
Commerce Cloud HIGH 7.5
CVE-2019-0322

SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent l…

Mitigation only
Fix from $1,950 2019-07-10
Openui5 MEDIUM 6.1
CVE-2019-0281

SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-controlled inputs, resulting in C…

Fix: 1.38.39 / 1.44.39+
Fix from $1,600 2019-07-10
Netweaver Application Server Abap MEDIUM 6.1
CVE-2019-0321

ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip…

Mitigation only
Fix from $1,600 2019-07-10