Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver Application Server Java MEDIUM 5.3
CVE-2019-0318

Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker…

Mitigation only
Fix from $1,600 2019-07-10
Businessobjects MEDIUM 6.1
CVE-2019-0303

SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested…

Mitigation only
Fix from $1,600 2019-06-14
Netweaver Process Integration HIGH 7.5
CVE-2019-0315

Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31,…

Mitigation only
Fix from $1,950 2019-06-12
R\/3 Enterprise MEDIUM 6.1
CVE-2019-0311

Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-contr…

Mitigation only
Fix from $1,600 2019-06-12
Work Manager MEDIUM 5.5
CVE-2019-0314

SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a ser…

Mitigation only
Fix from $1,600 2019-06-12
Netweaver Process Integration MEDIUM 5.3
CVE-2019-0312

Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to…

Mitigation only
Fix from $1,600 2019-06-12
Advanced Business Application Programming Platform Kernel CRITICAL 9.8
CVE-2019-0304

FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.…

Mitigation only
Fix from $2,300 2019-06-12
E Commerce MEDIUM 6.8
CVE-2019-0308

An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the pro…

Mitigation only
Fix from $1,600 2019-06-12
Identity Management HIGH 8.8
CVE-2019-0301

Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface …

Mitigation only
Fix from $1,950 2019-05-14
Treasury And Risk Management HIGH 8.8
CVE-2019-0280

SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform nec…

Mitigation only
Fix from $1,950 2019-05-14
Businessobjects HIGH 7.6
CVE-2019-0287

Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to …

No fix yet
Fix from $1,950 2019-05-14
Businessobjects HIGH 7.1
CVE-2019-0289

Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access i…

Mitigation only
Fix from $1,950 2019-05-14
Sap Solution Manager System MEDIUM 6.5
CVE-2019-0293

Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC de…

Mitigation only
Fix from $1,600 2019-05-14
E Commerce MEDIUM 6.1
CVE-2019-0298

SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulner…

Mitigation only
Fix from $1,600 2019-05-14
Solution Manager MEDIUM 5.5
CVE-2019-0291

Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.

No fix yet
Fix from $1,600 2019-05-14
Crystal Reports CRITICAL 9.8
CVE-2019-0285EPSS 7%

The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including crede…

No fix yet
Fix from $2,300 2019-04-10
Business Application Software Integrated Solution HIGH 8.8
CVE-2019-0279

ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to…

Fix: after 7.53
Fix from $1,950 2019-04-10
Netweaver Process Integration HIGH 7.1
CVE-2019-0283

SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofi…

Mitigation only
Fix from $1,950 2019-04-10
Hana MEDIUM 6.0
CVE-2019-0284

SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attac…

Mitigation only
Fix from $1,600 2019-04-10
Netweaver Process Integration MEDIUM 5.3
CVE-2019-0282

Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed w…

Mitigation only
Fix from $1,600 2019-04-10
Advanced Business Application Programming Platform Kernel HIGH 8.8
CVE-2019-0270

ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of p…

Mitigation only
Fix from $1,950 2019-03-12
Banking Services From Sap HIGH 8.8
CVE-2019-0276

Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorizatio…

Mitigation only
Fix from $1,950 2019-03-12
Businessobjects Business Intelligence HIGH 8.1
CVE-2019-0268

SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepte…

Mitigation only
Fix from $1,950 2019-03-12
Mobile Platform Sdk HIGH 7.5
CVE-2019-0274

SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service (i.e. den…

Mitigation only
Fix from $1,950 2019-03-12
Advanced Business Application Programming Platform MEDIUM 6.5
CVE-2019-0271

ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, lea…

Fix: after 7.52
Fix from $1,600 2019-03-12
Hana Extended Application Services MEDIUM 6.5
CVE-2019-0277

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer w…

Mitigation only
Fix from $1,600 2019-03-12
Businessobjects Business Intelligence MEDIUM 5.4
CVE-2019-0269

SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resul…

Mitigation only
Fix from $1,600 2019-03-12
Netweaver Application Server Java MEDIUM 5.4
CVE-2019-0275

SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not …

Fix: after 7.11
Fix from $1,600 2019-03-12
Manufacturing Integration And Intelligence HIGH 8.8
CVE-2019-0267

SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This…

Mitigation only
Fix from $1,950 2019-02-15
Hana Extended Application Services HIGH 7.5
CVE-2019-0266

Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a …

Mitigation only
Fix from $1,950 2019-02-15