Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Businessobjects CRITICAL 9.8
CVE-2019-0259

SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file for…

Mitigation only
Fix from $2,300 2019-02-15
Landscape Management CRITICAL 9.8
CVE-2019-0261

Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for…

Mitigation only
Fix from $2,300 2019-02-15
Netweaver Application Server Abap HIGH 8.8
CVE-2019-0257

Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.…

Fix: after 7.75
Fix from $1,950 2019-02-15
Disclosure Management HIGH 8.8
CVE-2019-0258

SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privi…

Mitigation only
Fix from $1,950 2019-02-15
Businessobjects Bi Platform MEDIUM 5.4
CVE-2019-0262

SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cro…

Mitigation only
Fix from $1,600 2019-02-15
Advanced Business Application Programming Platform Kernel HIGH 8.1
CVE-2019-0255

SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Serv…

Mitigation only
Fix from $1,950 2019-02-15
Businessobjects MEDIUM 6.1
CVE-2019-0251

The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site…

Mitigation only
Fix from $1,600 2019-02-15
Business One MEDIUM 5.5
CVE-2019-0256

Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restr…

No fix yet
Fix from $1,600 2019-02-15
Disclosure Management MEDIUM 5.4
CVE-2019-0254

SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XS…

Fix: 10.1+
Fix from $1,600 2019-02-15
Landscape Management HIGH 7.5
CVE-2019-0249

Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted.

Mitigation only
Fix from $1,950 2019-01-08
Cloud Connector CRITICAL 9.8
CVE-2019-0246

SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.

Fix: 2.11.3+
Fix from $2,300 2019-01-08
Cloud Connector CRITICAL 9.8
CVE-2019-0247

SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby cont…

Fix: 2.11.3+
Fix from $2,300 2019-01-08
Sapscore HIGH 8.8
CVE-2018-2484

SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.0…

Mitigation only
Fix from $1,950 2019-01-08
Bw\/4hana HIGH 8.8
CVE-2019-0243

Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform necessary authorization check…

Mitigation only
Fix from $1,950 2019-01-08
Financial Consolidation Cube Designer HIGH 7.5
CVE-2018-2499

A security weakness in SAP Financial Consolidation Cube Designer (BOBJ_EADES fixed in versions 8.0, 10.1) may allow an attacker to discover the passw…

Mitigation only
Fix from $1,950 2019-01-08
Businessobjects Mobile HIGH 7.5
CVE-2019-0240

SAP Business Objects Mobile for Android (before 6.3.5) application allows an attacker to provide malicious input in the form of a SAP BI link, preven…

Fix: 6.3.5+
Fix from $1,950 2019-01-08
Work Manager HIGH 7.5
CVE-2019-0241

SAP Work and Inventory Manager (Agentry_SDK , before 7.0, 7.1) allows an attacker to prevent legitimate users from accessing a service, either by cra…

Mitigation only
Fix from $1,950 2019-01-08
Hybris MEDIUM 6.1
CVE-2019-0238

SAP Commerce (previously known as SAP Hybris Commerce), before version 6.7, does not sufficiently encode user-controlled inputs, resulting in Cross-S…

Fix: 6.7+
Fix from $1,600 2019-01-08
Netweaver MEDIUM 5.9
CVE-2019-0248

Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to acces…

Mitigation only
Fix from $1,600 2019-01-08
Customer Relationship Management Webclient Ui MEDIUM 5.4
CVE-2019-0244

SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inp…

Mitigation only
Fix from $1,600 2019-01-08
Customer Relationship Management Webclient Ui MEDIUM 5.4
CVE-2019-0245

SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inp…

Mitigation only
Fix from $1,600 2019-01-08
Business Application Software Integrated Solution HIGH 8.0
CVE-2018-2494

Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeave…

Fix: after 7.53
Fix from $1,950 2018-12-11
Netweaver Application Server Java HIGH 7.4
CVE-2018-2503

By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been…

Mitigation only
Fix from $1,950 2018-12-11
Netweaver Application Server Java HIGH 7.1
CVE-2018-2492

SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in ver…

Mitigation only
Fix from $1,950 2018-12-11
Business One On Hana MEDIUM 6.1
CVE-2018-2502

TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using …

Mitigation only
Fix from $1,600 2018-12-11
Netweaver Application Server Java MEDIUM 6.1
CVE-2018-2504

SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulatio…

Mitigation only
Fix from $1,600 2018-12-11
Hybris MEDIUM 6.1
CVE-2018-2505

SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are bas…

Mitigation only
Fix from $1,600 2018-12-11
Marketing Sapscore MEDIUM 5.4
CVE-2018-2486

SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripti…

No fix yet
Fix from $1,600 2018-12-11
Fiori Client HIGH 7.8
CVE-2018-2491

When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL cont…

Fix: 1.11.5+
Fix from $1,950 2018-11-13
Netweaver HIGH 8.8
CVE-2018-2477

Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an …

Mitigation only
Fix from $1,950 2018-11-13