Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver Application Server Java MEDIUM 6.1
CVE-2018-2452

The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, result…

Mitigation only
Fix from $1,600 2018-09-11
Supplier Relationship Management Mdm Catalog HIGH 8.6
CVE-2018-2449

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid reposito…

Mitigation only
Fix from $1,950 2018-08-14
Businessobjects Business Intelligence HIGH 7.5
CVE-2018-2446

Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name…

Mitigation only
Fix from $1,950 2018-08-14
Maxdb HIGH 7.2
CVE-2018-2450

SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore re…

Mitigation only
Fix from $1,950 2018-08-14
Hana Extended Application Services MEDIUM 6.6
CVE-2018-2451

XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentio…

Patch available
Fix from $1,600 2018-08-14
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2018-2447

SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposi…

Mitigation only
Fix from $1,600 2018-08-14
Supplier Relationship Management Mdm Catalog MEDIUM 5.3
CVE-2018-2448

Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user exis…

Mitigation only
Fix from $1,600 2018-08-14
Businessobjects Business Intelligence CRITICAL 9.6
CVE-2018-2445

AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft…

Mitigation only
Fix from $2,300 2018-08-14
Businessobjects Business Intelligence HIGH 8.8
CVE-2018-2442

In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session …

Mitigation only
Fix from $1,950 2018-08-14
Businessobjects Financial Consolidation MEDIUM 6.1
CVE-2018-2444

SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script…

Mitigation only
Fix from $1,600 2018-08-14
Sap Kernel MEDIUM 5.5
CVE-2018-2441

Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unico…

No fix yet
Fix from $1,600 2018-08-14
Business Planning And Consolidation HIGH 8.1
CVE-2017-16349

An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e…

Mitigation only
Fix from $1,950 2018-08-02
Internet Graphics Server CRITICAL 9.1
CVE-2018-2437

The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can l…

Mitigation only
Fix from $2,300 2018-07-10
R\/3 Enterprise Retail HIGH 8.8
CVE-2018-2436

Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting i…

Mitigation only
Fix from $1,950 2018-07-10
Internet Graphics Server HIGH 7.5
CVE-2018-2438

The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prev…

Mitigation only
Fix from $1,950 2018-07-10
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2018-2435

SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting …

Fix: after 7.02
Fix from $1,600 2018-07-10
Internet Graphics Server MEDIUM 5.9
CVE-2018-2439

The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is valid…

Mitigation only
Fix from $1,600 2018-07-10
Businessobjects Business Intelligence HIGH 8.8
CVE-2018-2427

SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allow…

Patch available
Fix from $1,950 2018-07-10
Sap Kernel HIGH 7.5
CVE-2018-2433

SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.2…

Mitigation only
Fix from $1,950 2018-07-10
Businessobjects Business Intelligence MEDIUM 6.1
CVE-2018-2431

SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site…

Patch available
Fix from $1,600 2018-07-10
Businessobjects Business Intelligence MEDIUM 5.4
CVE-2018-2432

SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include inv…

Patch available
Fix from $1,600 2018-07-10
Hana Database HIGH 7.5
CVE-2018-2424

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to th…

Mitigation only
Fix from $1,950 2018-06-12
Business One MEDIUM 5.5
CVE-2018-2425

Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be r…

Mitigation only
Fix from $1,600 2018-06-12
Infrastructure MEDIUM 5.3
CVE-2018-2428

Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected a…

Mitigation only
Fix from $1,600 2018-06-12
Internet Transaction Server MEDIUM 6.1
CVE-2018-11415EPSS 8%

SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indic…

No fix yet
Fix from $1,600 2018-05-24
Internet Graphics Server HIGH 7.5
CVE-2018-2422

SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…

Mitigation only
Fix from $1,950 2018-05-09
Internet Graphics Server HIGH 7.5
CVE-2018-2423

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from access…

Mitigation only
Fix from $1,950 2018-05-09
Maxdb Odbc Driver CRITICAL 9.8
CVE-2018-2418

SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could th…

Fix: 7.9.09.07+
Fix from $2,300 2018-05-09
Internet Graphics Server CRITICAL 9.8
CVE-2018-2420

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi…

Mitigation only
Fix from $2,300 2018-05-09
Internet Graphics Server HIGH 7.5
CVE-2018-2421

SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…

Mitigation only
Fix from $1,950 2018-05-09