Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Identity Management MEDIUM 5.4
CVE-2018-2416

SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.

Mitigation only
Fix from $1,600 2018-05-09
Identity Management MEDIUM 5.3
CVE-2018-2417

Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be re…

Mitigation only
Fix from $1,600 2018-05-09
Disclosure Management CRITICAL 9.8
CVE-2018-2404

SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.

Mitigation only
Fix from $2,300 2018-04-10
Cloud Platform HIGH 8.8
CVE-2018-2409

Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some othe…

Mitigation only
Fix from $1,950 2018-04-10
Disclosure Management HIGH 8.8
CVE-2018-2412

SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Mitigation only
Fix from $1,950 2018-04-10
Disclosure Management HIGH 8.8
CVE-2018-2413

SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Mitigation only
Fix from $1,950 2018-04-10
Businessobjects HIGH 7.3
CVE-2018-2408

Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password ch…

Mitigation only
Fix from $1,950 2018-04-10
Disclosure Management MEDIUM 6.5
CVE-2018-2403

Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible…

Mitigation only
Fix from $1,600 2018-04-10
Solution Manager MEDIUM 5.4
CVE-2018-2405

SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lea…

Mitigation only
Fix from $1,600 2018-04-10
Business One MEDIUM 5.4
CVE-2018-2410

SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnera…

Mitigation only
Fix from $1,600 2018-04-10
Crystal Reports Server MEDIUM 5.3
CVE-2018-2406

Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup p…

Mitigation only
Fix from $1,600 2018-04-10
Hana HIGH 8.4
CVE-2018-2402

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & r…

Mitigation only
Fix from $1,950 2018-03-14
Business Client HIGH 7.5
CVE-2018-2398

Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.

No fix yet
Fix from $1,950 2018-03-14
Process Monitoring Infrastructure MEDIUM 6.1
CVE-2018-2399

Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user contr…

Mitigation only
Fix from $1,600 2018-03-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2018-2397

In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode use…

Mitigation only
Fix from $1,600 2018-03-14
Netweaver System Landscape Directory CRITICAL 9.8
CVE-2018-2368

SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that r…

Mitigation only
Fix from $2,300 2018-03-01
Business Application Software Integrated Solution HIGH 8.8
CVE-2018-2367

ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insuffici…

Fix: after 7.52
Fix from $1,950 2018-03-01
Customer Relationship Management MEDIUM 6.6
CVE-2018-2380 KEVEPSS 29%

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus charact…

Mitigation only
Fix from $1,600 2018-03-01
Netweaver Portal MEDIUM 6.1
CVE-2018-2365

SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting …

Mitigation only
Fix from $1,600 2018-03-01
Internet Graphics Server HIGH 8.8
CVE-2018-2395

Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite e…

Mitigation only
Fix from $1,950 2018-02-14
Internet Graphics Server HIGH 7.5
CVE-2018-2392EPSS 41%

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus…

Mitigation only
Fix from $1,950 2018-02-14
Internet Graphics Server HIGH 7.5
CVE-2018-2393EPSS 15%

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus…

Mitigation only
Fix from $1,950 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2384

Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics …

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2385

Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Serv…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2386

Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from accessing the SAP Internet Gra…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2387

A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to obtain information on ports, wh…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2390

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2391

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2394

Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, …

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2396

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.…

No fix yet
Fix from $1,600 2018-02-14