Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hana HIGH 7.5
CVE-2015-7994

The SQL interface in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via unspecified vectors related t…

No fix yet
Fix from $1,950 2015-11-10
Hana HIGH 7.5
CVE-2015-7993

The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary …

No fix yet
Fix from $1,950 2015-11-10
Hana MEDIUM 5.0
CVE-2015-7991

The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to read web dispatcher and security trace files an…

No fix yet
Fix from $1,600 2015-11-10
Hana HIGH 10.0
CVE-2015-7828EPSS 7%

SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified o…

Fix: after 1.00
Fix from $1,950 2015-11-10
3d Visual Enterprise Viewer MEDIUM 6.8
CVE-2015-8030

SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted (1) U3D, (2) LWO, (3) JPEG2000, or (4) FBX file…

Mitigation only
Fix from $1,600 2015-10-30
3d Visual Enterprise Viewer MEDIUM 6.8
CVE-2015-8029

SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted Filmbox document, which triggers memory corrupt…

Mitigation only
Fix from $1,600 2015-10-30
3d Visual Enterprise Viewer MEDIUM 6.8
CVE-2015-8028

Multiple buffer overflows in SAP 3D Visual Enterprise Viewer (VEV) allow remote attackers to execute arbitrary code via a crafted (1) 3DM or (2) Flic…

Mitigation only
Fix from $1,600 2015-10-30
Hana HIGH 7.5
CVE-2015-7986EPSS 6%

The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupt…

Fix: after 1.00.095
Fix from $1,950 2015-10-27
Businessobjects HIGH 10.0
CVE-2015-7730

SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2015-10-15
Hana MEDIUM 6.5
CVE-2015-7729

Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenti…

No fix yet
Fix from $1,600 2015-10-15
Hana MEDIUM 6.5
CVE-2015-7727

Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allow remote authentica…

No fix yet
Fix from $1,600 2015-10-15
Hana MEDIUM 6.5
CVE-2015-7725

Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allow remote authenticated users …

No fix yet
Fix from $1,600 2015-10-15
Hana HIGH 7.2
CVE-2015-6507

The hdbsql client 1.00.091.00 Build 1418659308-1530 in SAP HANA allows local users to cause a denial of service (memory corruption) and possibly have…

No fix yet
Fix from $1,950 2015-10-15
Netweaver J2ee Engine HIGH 7.5
CVE-2015-7239

SQL injection vulnerability in the BP_FIND_JOBS_WITH_PROGRAM function module in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arb…

No fix yet
Fix from $1,950 2015-09-18
Mobile Platform MEDIUM 6.8
CVE-2015-6664

XML external entity (XXE) vulnerability in the application import functionality in SAP Mobile Platform 2.3 allows remote attackers to read arbitrary …

No fix yet
Fix from $1,600 2015-08-24
Netweaver MEDIUM 6.8
CVE-2015-6662

XML external entity (XXE) vulnerability in SAP NetWeaver Portal 7.4 allows remote attackers to read arbitrary files and possibly have other unspecifi…

No fix yet
Fix from $1,600 2015-08-24
Enterprise Central Component HIGH 9.3
CVE-2015-3621

Untrusted search path vulnerability in SAP Enterprise Central Component (ECC) allows local users to gain privileges via a Trojan horse program.

No fix yet
Fix from $1,950 2015-07-16
Afaria HIGH 7.2
CVE-2015-3449

The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local use…

No fix yet
Fix from $1,950 2015-07-16
Mobile Platform HIGH 7.5
CVE-2015-5068

XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to read arbitrary files or possibly have other unspecified i…

No fix yet
Fix from $1,950 2015-06-24
Netweaver HIGH 7.5
CVE-2015-5067

The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows remote attackers to obtain acces…

No fix yet
Fix from $1,950 2015-06-24
Afaria HIGH 7.5
CVE-2015-4161

SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensitive information, gain privil…

No fix yet
Fix from $1,950 2015-06-02
Ase Database Platform HIGH 7.5
CVE-2015-4160

SQL injection vulnerability in SAP ASE Database Platform allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP S…

No fix yet
Fix from $1,950 2015-06-02
Hana Web Based Development Workbench HIGH 7.5
CVE-2015-4159

SQL injection vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to execute arbitrary SQL commands via unspecified vec…

No fix yet
Fix from $1,950 2015-06-02
Netweaver Abap Application Server MEDIUM 5.0
CVE-2015-4158

SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121…

No fix yet
Fix from $1,600 2015-06-02
Content Server MEDIUM 5.0
CVE-2015-4157

SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.

No fix yet
Fix from $1,600 2015-06-02
Gui HIGH 7.5
CVE-2015-2282

Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6,…

No fix yet
Fix from $1,950 2015-06-02
Gui MEDIUM 5.0
CVE-2015-2278

The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server …

No fix yet
Fix from $1,600 2015-06-02
Afaria HIGH 7.5
CVE-2015-4092

Buffer overflow in the XComms process in SAP Afaria 7.00.6620.2 SP5 allows remote attackers to cause a denial of service (crash) or possibly execute …

Mitigation only
Fix from $1,950 2015-05-26
Sap Netweaver Application Server Java HIGH 7.5
CVE-2015-4091

XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly hav…

No fix yet
Fix from $1,950 2015-05-26
Netweaver Rfc Sdk MEDIUM 5.0
CVE-2015-3981

SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037.

No fix yet
Fix from $1,600 2015-05-12