Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Disclosure Management HIGH 8.3
CVE-2018-2487

SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use c…

Mitigation only
Fix from $1,950 2018-11-13
Fiori Client HIGH 7.8
CVE-2018-2488

It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client an…

Fix: 1.11.5+
Fix from $1,950 2018-11-13
Fiori Client HIGH 7.8
CVE-2018-2489

Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client. SAP Fiori Client version 1.…

Fix: 1.11.5+
Fix from $1,950 2018-11-13
Fiori Client HIGH 7.8
CVE-2018-2490

The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in Google Play store addresses …

Fix: 1.11.5+
Fix from $1,950 2018-11-13
Fiori Client HIGH 7.7
CVE-2018-2485

It is possible for a malicious application or malware to execute JavaScript in a SAP Fiori application. This can include reading and writing of infor…

Fix: 1.11.5+
Fix from $1,950 2018-11-13
Mobile Secure HIGH 7.5
CVE-2018-2482

SAP Mobile Secure Android Application, Mobile-secure.apk Android client, before version 6.60.19942.0, allows an attacker to prevent legitimate users …

Fix: 6.60.19942.0+
Fix from $1,950 2018-11-13
Basis HIGH 7.2
CVE-2018-2478

An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to …

Fix: after 7.53
Fix from $1,950 2018-11-13
Advanced Business Application Programming HIGH 7.2
CVE-2018-2481

In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a transaction code reserved for cust…

Fix: after 7.11
Fix from $1,950 2018-11-13
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2018-2473

SAP BusinessObjects Business Intelligence Platform Server, versions 4.1 and 4.2, when using Web Intelligence Richclient 3 tiers mode gateway allows a…

Mitigation only
Fix from $1,600 2018-11-13
Netweaver MEDIUM 6.1
CVE-2018-2476

Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.

Mitigation only
Fix from $1,600 2018-11-13
Businessobjects Bi Platform MEDIUM 6.1
CVE-2018-2479

SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resultin…

Mitigation only
Fix from $1,600 2018-11-13
Fiori MEDIUM 6.5
CVE-2018-2474

SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended req…

Mitigation only
Fix from $1,600 2018-10-09
Adaptive Server Enterprise HIGH 7.5
CVE-2018-2468

Under certain conditions the backup server in SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information …

Mitigation only
Fix from $1,950 2018-10-09
Adaptive Server Enterprise HIGH 7.5
CVE-2018-2469

Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise…

Mitigation only
Fix from $1,950 2018-10-09
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2018-2471

Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherw…

No fix yet
Fix from $1,950 2018-10-09
Netweaver MEDIUM 6.1
CVE-2018-2470

In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-…

Fix: after 7.53
Fix from $1,600 2018-10-09
Businessobjects Bi Platform MEDIUM 6.1
CVE-2018-2472

SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs,…

Mitigation only
Fix from $1,600 2018-10-09
Businessobjects Bi Platform MEDIUM 5.3
CVE-2018-2467

In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser su…

Mitigation only
Fix from $1,600 2018-10-09
Data Services MEDIUM 5.4
CVE-2018-2466

In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate user-controlled inputs, which…

Mitigation only
Fix from $1,600 2018-10-09
Hana HIGH 7.5
CVE-2018-2465

SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauth…

Mitigation only
Fix from $1,950 2018-09-11
Netweaver MEDIUM 6.1
CVE-2018-2464

SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scri…

Mitigation only
Fix from $1,600 2018-09-11
People Profile HIGH 8.8
CVE-2018-2461

Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of p…

Mitigation only
Fix from $1,950 2018-09-11
Netweaver HIGH 8.8
CVE-2018-2462

In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML doc…

Mitigation only
Fix from $1,950 2018-09-11
Hybris HIGH 8.6
CVE-2018-2463

The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to…

Fix: after 6.7
Fix from $1,950 2018-09-11
Business One HIGH 7.5
CVE-2018-2458

Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which…

No fix yet
Fix from $1,950 2018-09-11
Mobile Platform HIGH 7.5
CVE-2018-2459

Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occ…

Mitigation only
Fix from $1,950 2018-09-11
Adaptive Server Enterprise MEDIUM 6.5
CVE-2018-2457

Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access information which would otherwise be re…

No fix yet
Fix from $1,600 2018-09-11
Business One MEDIUM 5.9
CVE-2018-2460

SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM att…

Mitigation only
Fix from $1,600 2018-09-11
Enterprise Financial Services HIGH 8.8
CVE-2018-2454

SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary aut…

Mitigation only
Fix from $1,950 2018-09-11
Enterprise Financial Services HIGH 8.8
CVE-2018-2455

SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary …

Mitigation only
Fix from $1,950 2018-09-11