Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Business Warehouse Universal Data Integration MEDIUM 6.1
CVE-2017-16685

Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient…

Mitigation only
Fix from $1,600 2017-12-12
Hana Database MEDIUM 5.3
CVE-2017-16687

The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,…

Mitigation only
Fix from $1,600 2017-12-12
Businessobjects Financial Consolidation MEDIUM 6.1
CVE-2017-14516

Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292.

Mitigation only
Fix from $1,600 2017-12-03
Point Of Sale Xpress Server CRITICAL 9.8
CVE-2017-15295

Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.

Mitigation only
Fix from $2,300 2017-10-16
Customer Relationship Management HIGH 8.8
CVE-2017-15296

The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.

No fix yet
Fix from $1,950 2017-10-16
Host Agent HIGH 7.5
CVE-2017-15297

SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.

Mitigation only
Fix from $1,950 2017-10-16
Point Of Sale Xpress Server CRITICAL 9.8
CVE-2017-15293

Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at…

Mitigation only
Fix from $2,300 2017-10-16
Customer Relationship Management MEDIUM 6.1
CVE-2017-15294

The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

Mitigation only
Fix from $1,600 2017-10-16
Enterprise Portal MEDIUM 6.1
CVE-2017-10701

Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Securi…

Fix: after 7.50
Fix from $1,600 2017-09-29
Netweaver Application Server Java HIGH 7.5
CVE-2017-14581

The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a craf…

Fix: after 7.50
Fix from $1,950 2017-09-19
E Recruiting HIGH 7.5
CVE-2017-14511

An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/…

Mitigation only
Fix from $1,950 2017-09-17
Netweaver CRITICAL 9.8
CVE-2015-7241EPSS 12%

XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.

Fix: after 7.0
Fix from $2,300 2017-09-06
Hybris HIGH 7.5
CVE-2014-8871

Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlie…

Fix: after 5.3.0.1
Fix from $1,950 2017-08-28
Netweaver Application Server Java HIGH 7.5
CVE-2017-12637 KEVEPSS 95%

Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a…

Mitigation only
Fix from $1,950 2017-08-07
Trex CRITICAL 9.8
CVE-2017-11459

SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr…

Mitigation only
Fix from $2,300 2017-07-25
Netweaver Application Server Java MEDIUM 6.5
CVE-2017-11457

XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o…

Mitigation only
Fix from $1,600 2017-07-25
Netweaver Application Server Java MEDIUM 6.1
CVE-2017-11458

Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary…

Mitigation only
Fix from $1,600 2017-07-25
Netweaver Portal MEDIUM 6.1
CVE-2017-11460

Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary …

Mitigation only
Fix from $1,600 2017-07-25
Netweaver HIGH 7.5
CVE-2017-9844EPSS 6%

SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java…

Mitigation only
Fix from $1,950 2017-07-12
Netweaver HIGH 7.5
CVE-2017-9845

disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG reque…

Mitigation only
Fix from $1,950 2017-07-12
Successfactors MEDIUM 5.4
CVE-2017-9613

Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web …

No fix yet
Fix from $1,600 2017-06-15
Business One CRITICAL 9.6
CVE-2016-6256EPSS 8%

SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell…

No fix yet
Fix from $2,300 2017-05-26
Netweaver Application Server Java HIGH 8.8
CVE-2017-8913

The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks…

Mitigation only
Fix from $1,950 2017-05-23
Hana Xs HIGH 8.3
CVE-2017-8914

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user …

Mitigation only
Fix from $1,950 2017-05-23
Hana Xs HIGH 7.5
CVE-2017-8915

sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing …

Mitigation only
Fix from $1,950 2017-05-23
Sapcar HIGH 7.8
CVE-2017-8852

SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted r…

No fix yet
Fix from $1,950 2017-05-10
Netweaver Application Server Java HIGH 8.8
CVE-2017-7717

SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users…

Mitigation only
Fix from $1,950 2017-04-14
Sso Authentication Library HIGH 7.5
CVE-2017-7696EPSS 36%

SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in t…

Mitigation only
Fix from $1,950 2017-04-14
Business Intelligence Platform CRITICAL 9.8
CVE-2016-6818

SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify…

Mitigation only
Fix from $2,300 2017-04-13
Hana CRITICAL 9.8
CVE-2016-6143

SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.

Mitigation only
Fix from $2,300 2017-04-13