Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Internet Graphics Server MEDIUM 6.1
CVE-2018-2383

Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.1
CVE-2018-2388

Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 5.7
CVE-2018-2389

Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding importa…

Mitigation only
Fix from $1,600 2018-02-14
Erp Financials Information System HIGH 8.8
CVE-2018-2381

SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.0…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services HIGH 8.1
CVE-2018-2375

In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application e…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services HIGH 8.1
CVE-2018-2376

In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application e…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services HIGH 7.5
CVE-2018-2373

Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that del…

Mitigation only
Fix from $1,950 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2372

A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL…

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2374

In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive app…

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2377

In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2378

In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumpti…

Mitigation only
Fix from $1,600 2018-02-14
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2379

In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a spe…

Mitigation only
Fix from $1,600 2018-02-14
Internet Graphics Server MEDIUM 6.5
CVE-2018-2382

A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled …

Mitigation only
Fix from $1,600 2018-02-14
Customer Relationship Management Webclient Ui MEDIUM 6.1
CVE-2018-2364

SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in C…

Mitigation only
Fix from $1,600 2018-02-14
Netweaver Java Web Application MEDIUM 6.1
CVE-2018-2371

The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in C…

Mitigation only
Fix from $1,600 2018-02-14
Hana MEDIUM 5.3
CVE-2018-2369

Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attac…

Mitigation only
Fix from $1,600 2018-02-14
Bi Launchpad MEDIUM 5.3
CVE-2018-2370

Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, …

Mitigation only
Fix from $1,600 2018-02-14
Solution Manager HIGH 8.8
CVE-2018-2361

In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required…

Mitigation only
Fix from $1,950 2018-01-09
Netweaver HIGH 8.8
CVE-2018-2363

SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrar…

Fix: after 7.52
Fix from $1,950 2018-01-09
Sap Kernel HIGH 7.5
CVE-2018-2360

SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause con…

Mitigation only
Fix from $1,950 2018-01-09
Hana MEDIUM 5.3
CVE-2018-2362

A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose informa…

Mitigation only
Fix from $1,600 2018-01-09
Business Intelligence Promotion Management Application CRITICAL 9.8
CVE-2017-16684

SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti…

Mitigation only
Fix from $2,300 2017-12-12
Sap Kernel HIGH 8.8
CVE-2017-16689

A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f…

Mitigation only
Fix from $1,950 2017-12-12
Plant Connectivity HIGH 7.8
CVE-2017-16690

A malicious DLL preload attack possible on NwSapSetup and Installation self-extracting program for SAP Plant Connectivity 2.3 and 15.0. It is possibl…

Mitigation only
Fix from $1,950 2017-12-12
Hana Extended Application Services HIGH 7.5
CVE-2017-16680

Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller servic…

Mitigation only
Fix from $1,950 2017-12-12
Netweaver Internet Transaction Server HIGH 7.2
CVE-2017-16682

SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administra…

Fix: after 7.52
Fix from $1,950 2017-12-12
Businessobjects MEDIUM 6.5
CVE-2017-16683

Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from acc…

Mitigation only
Fix from $1,600 2017-12-12
Business Application Software Integrated Solution MEDIUM 6.5
CVE-2017-16691

SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note…

Mitigation only
Fix from $1,600 2017-12-12
Sap Kernel MEDIUM 6.1
CVE-2017-16679

URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21…

Mitigation only
Fix from $1,600 2017-12-12
Business Intelligence Promotion Management Application MEDIUM 6.1
CVE-2017-16681

Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controll…

Mitigation only
Fix from $1,600 2017-12-12