Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Trex CRITICAL 9.8
CVE-2016-6140EPSS 6%

SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591.

No fix yet
Fix from $2,300 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6139

SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.

No fix yet
Fix from $2,300 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6138EPSS 6%

Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Secur…

No fix yet
Fix from $2,300 2016-08-05
Hana Db MEDIUM 5.5
CVE-2016-3640

The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obtain sensitive password informa…

Mitigation only
Fix from $1,600 2016-08-05
Netweaver Application Server Java CRITICAL 10.0
CVE-2010-5326 KEVEPSS 17%

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote att…

Fix: after 7.30
Fix from $2,300 2016-05-13
Hana HIGH 7.5
CVE-2016-4017

The Data Provisioning Agent (aka DP Agent) in SAP HANA allows remote attackers to cause a denial of service (process crash) via unspecified vectors, …

Mitigation only
Fix from $1,950 2016-04-14
Hana HIGH 7.3
CVE-2016-4018

The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to o…

Mitigation only
Fix from $1,950 2016-04-14
Java As MEDIUM 6.1
CVE-2016-4016

Cross-site scripting (XSS) vulnerability in SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) 15 allows remote attackers to inj…

No fix yet
Fix from $1,600 2016-04-14
Netweaver HIGH 7.5
CVE-2016-4015

The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted reques…

Mitigation only
Fix from $1,950 2016-04-14
Netweaver HIGH 8.6
CVE-2016-4014EPSS 5%

XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (syst…

No fix yet
Fix from $1,950 2016-04-14
Application Server Java HIGH 7.5
CVE-2016-3980EPSS 7%

The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a cra…

Fix: after 7.4
Fix from $1,950 2016-04-08
Java As HIGH 7.5
CVE-2016-3979EPSS 6%

Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory co…

No fix yet
Fix from $1,950 2016-04-08
Netweaver Application Server Java HIGH 8.8
CVE-2015-8840

The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sen…

Mitigation only
Fix from $1,950 2016-04-08
Netweaver Application Server Java HIGH 7.5
CVE-2016-3976 KEVEPSS 47%

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backsla…

Fix: after 7.50
Fix from $1,950 2016-04-07
Netweaver Application Server Java MEDIUM 6.1
CVE-2016-3975

Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via …

Fix: after 7.50
Fix from $1,600 2016-04-07
Netweaver Application Server Java CRITICAL 9.1
CVE-2016-3974EPSS 15%

XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denia…

Fix: after 7.50
Fix from $2,300 2016-04-07
Netweaver Application Server Java MEDIUM 5.3
CVE-2016-3973

The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain…

Fix: after 7.50
Fix from $1,600 2016-04-07
3d Visual Enterprise Viewer HIGH 8.8
CVE-2016-2536

Multiple use-after-free vulnerabilities in SAP 3D Visual Enterprise Viewer allow remote attackers to execute arbitrary code via a crafted SketchUp do…

Mitigation only
Fix from $1,950 2016-02-22
Netweaver HIGH 7.5
CVE-2016-2389EPSS 41%

Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP Net…

No fix yet
Fix from $1,950 2016-02-16
Netweaver Application Server Java MEDIUM 5.3
CVE-2016-2388 KEVEPSS 52%

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP req…

Fix: after 7.50
Fix from $1,600 2016-02-16
Netweaver MEDIUM 6.1
CVE-2016-2387

Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inje…

No fix yet
Fix from $1,600 2016-02-16
Netweaver Application Server Java CRITICAL 9.8
CVE-2016-2386 KEVEPSS 71%

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspec…

Mitigation only
Fix from $2,300 2016-02-16
Hana CRITICAL 9.3
CVE-2016-1929

The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption an…

Mitigation only
Fix from $2,300 2016-01-20
Hana CRITICAL 9.8
CVE-2016-1928EPSS 6%

Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a craft…

Mitigation only
Fix from $2,300 2016-01-20
Netweaver MEDIUM 6.1
CVE-2016-1911

Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors re…

Mitigation only
Fix from $1,600 2016-01-15
Netweaver MEDIUM 5.3
CVE-2016-1910EPSS 6%

The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

No fix yet
Fix from $1,600 2016-01-15
Afaria CRITICAL 9.1
CVE-2015-8753

SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insec…

Mitigation only
Fix from $2,300 2016-01-08
Mobile Platform HIGH 7.5
CVE-2015-8600

The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive information, gain privileges…

Mitigation only
Fix from $1,950 2015-12-17
Plant Connectivity HIGH 7.8
CVE-2015-8330

The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption and agent crash) via crafted xM…

No fix yet
Fix from $1,950 2015-11-24
Manufacturing Integration And Intelligence MEDIUM 5.0
CVE-2015-8329

SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct down…

No fix yet
Fix from $1,600 2015-11-24