Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Trex CRITICAL 9.8
CVE-2017-7691

A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.

Mitigation only
Fix from $2,300 2017-04-11
Netweaver CRITICAL 9.8
CVE-2016-10311

Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to t…

Mitigation only
Fix from $2,300 2017-04-10
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-10304

The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and ser…

Mitigation only
Fix from $1,600 2017-04-10
Gui For Windows CRITICAL 9.8
CVE-2017-6950

SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, a…

Mitigation only
Fix from $2,300 2017-03-23
Sap Kernel HIGH 7.5
CVE-2017-5997

The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash…

Mitigation only
Fix from $1,950 2017-02-15
Saplpd HIGH 7.5
CVE-2016-10079EPSS 6%

SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.

Fix: after 7400.3.11.33
Fix from $1,950 2017-02-01
Netweaver HIGH 7.5
CVE-2017-5372

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system informati…

No fix yet
Fix from $1,950 2017-01-23
Hybris MEDIUM 6.1
CVE-2016-6856

Cross-site scripting (XSS) vulnerability in the Inbox Search feature in Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attack…

Fix: after 5.6.0.10
Fix from $1,600 2016-12-31
Hybris MEDIUM 5.4
CVE-2016-6857

Cross-site scripting (XSS) vulnerability in the Create Catalogue feature in Hybris Management Console (HMC) in SAP Hybris before 5.2.0.13, 5.3.x befo…

Fix: 5.2.0.13 / 5.3.0.11+
Fix from $1,600 2016-12-31
Hybris MEDIUM 5.4
CVE-2016-6858

Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x bef…

Fix: 5.0.4.11 / 5.1.0.11+
Fix from $1,600 2016-12-31
Solution Manager HIGH 7.5
CVE-2016-10005

Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~t…

No fix yet
Fix from $1,950 2016-12-19
Netweaver Application Server Java MEDIUM 6.5
CVE-2016-9563 KEVEPSS 24%

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi…

Mitigation only
Fix from $1,600 2016-11-23
Netweaver Application Server Java HIGH 7.5
CVE-2016-9562

SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the …

Mitigation only
Fix from $1,950 2016-11-23
Sapcryptolib MEDIUM 6.5
CVE-2016-4407

The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to imperson…

Mitigation only
Fix from $1,600 2016-10-13
Sapconsole HIGH 7.8
CVE-2016-3946

SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note …

Mitigation only
Fix from $1,950 2016-10-13
Sld Registration MEDIUM 5.5
CVE-2016-3638

SAP SLD Registration Program (aka SLDREG) allows local users to cause a denial of service (memory corruption and process termination) via a crafted H…

No fix yet
Fix from $1,600 2016-10-13
Netweaver HIGH 7.5
CVE-2016-3635

SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remot…

Mitigation only
Fix from $1,950 2016-10-13
Netweaver CRITICAL 9.1
CVE-2016-7435

The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.…

Mitigation only
Fix from $2,300 2016-10-05
Netweaver HIGH 7.5
CVE-2016-4551

The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to …

Mitigation only
Fix from $1,950 2016-10-05
Trex MEDIUM 5.3
CVE-2016-6146

The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security No…

No fix yet
Fix from $1,600 2016-09-27
Trex CRITICAL 9.8
CVE-2016-6137

An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security N…

No fix yet
Fix from $2,300 2016-09-27
Hana HIGH 7.5
CVE-2016-6142

SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to th…

No fix yet
Fix from $1,950 2016-09-26
Sapcar Archive Tool MEDIUM 5.8
CVE-2016-5847

SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted…

No fix yet
Fix from $1,600 2016-08-13
Sapcar MEDIUM 5.5
CVE-2016-5845

SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (prog…

No fix yet
Fix from $1,600 2016-08-13
Hana CRITICAL 9.8
CVE-2016-6150

The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended ac…

No fix yet
Fix from $2,300 2016-08-05
Hana Sps09 MEDIUM 5.5
CVE-2016-6149

SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Se…

No fix yet
Fix from $1,600 2016-08-05
Hana HIGH 7.5
CVE-2016-6148

SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors relate…

No fix yet
Fix from $1,950 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6147

An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified…

No fix yet
Fix from $2,300 2016-08-05
Hana Db MEDIUM 5.3
CVE-2016-6145

The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username…

No fix yet
Fix from $1,600 2016-08-05
Hana HIGH 8.1
CVE-2016-6144

The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_u…

Fix: after 1.00.73.00.389160
Fix from $1,950 2016-08-05