Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Customer Relationship Management HIGH 7.5
CVE-2015-3980

SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecifie…

Mitigation only
Fix from $1,950 2015-05-12
Customer Relationship Management HIGH 7.5
CVE-2015-3979

Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka…

Mitigation only
Fix from $1,950 2015-05-12
Afaria MEDIUM 5.0
CVE-2015-2820

Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process termination) via a crafted reque…

No fix yet
Fix from $1,600 2015-04-01
Sql Anywhere MEDIUM 5.0
CVE-2015-2819

SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.

No fix yet
Fix from $1,600 2015-04-01
Mobile Platform MEDIUM 5.0
CVE-2015-2818

XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SA…

Mitigation only
Fix from $1,600 2015-04-01
Netweaver MEDIUM 5.0
CVE-2015-2817

The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Secu…

No fix yet
Fix from $1,600 2015-04-01
Afaria HIGH 7.5
CVE-2015-2816

The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted req…

No fix yet
Fix from $1,950 2015-04-01
Netweaver MEDIUM 6.5
CVE-2015-2815

Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remo…

No fix yet
Fix from $1,600 2015-04-01
Clinical Task Tracker MEDIUM 6.4
CVE-2015-2814

SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which…

Mitigation only
Fix from $1,600 2015-04-01
Netweaver Enterprise Portal MEDIUM 5.0
CVE-2015-2812

XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests …

No fix yet
Fix from $1,600 2015-04-01
Mobile Platform MEDIUM 5.0
CVE-2015-2813

XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP …

No fix yet
Fix from $1,600 2015-04-01
Netweaver Enterprise Portal MEDIUM 5.0
CVE-2015-2811

XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intr…

No fix yet
Fix from $1,600 2015-04-01
Businessobjects Edge MEDIUM 5.0
CVE-2015-2076

The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note …

No fix yet
Fix from $1,600 2015-02-27
Businessobjects Edge MEDIUM 5.0
CVE-2015-2075

SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011…

No fix yet
Fix from $1,600 2015-02-27
Enterprise Resource Planning HIGH 7.5
CVE-2015-1312

The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and p…

Mitigation only
Fix from $1,950 2015-01-22
Hana Extended Application Services HIGH 10.0
CVE-2015-1311

The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 209890…

Mitigation only
Fix from $1,950 2015-01-22
Netweaver Abap MEDIUM 5.0
CVE-2015-1309

XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers …

Fix: after 7.31
Fix from $1,600 2015-01-22
Sap Kernel MEDIUM 6.5
CVE-2014-9595

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…

Mitigation only
Fix from $1,600 2015-01-15
Sap Kernel MEDIUM 6.5
CVE-2014-9594

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…

Mitigation only
Fix from $1,600 2015-01-15
Businessobjects HIGH 10.0
CVE-2014-9387

SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORB…

Mitigation only
Fix from $1,950 2014-12-17
Sql Anywhere HIGH 7.5
CVE-2014-9264

Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alia…

Mitigation only
Fix from $1,950 2014-12-11
Governance Risk And Compliance HIGH 9.0
CVE-2013-3678

Multiple unspecified vulnerabilities in SAP Governance, Risk, and Compliance (GRC) allow remote authenticated users to gain privileges and execute ar…

No fix yet
Fix from $1,950 2014-11-19
Customer Relationship Management Internet Sales HIGH 10.0
CVE-2014-8661

The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Customer Relationship Management HIGH 10.0
CVE-2014-8669EPSS 5%

The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Payroll Process HIGH 7.8
CVE-2014-8662

Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors related to session handling.

No fix yet
Fix from $1,950 2014-11-06
Netweaver Business Warehouse HIGH 7.5
CVE-2014-8663

SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands …

Mitigation only
Fix from $1,950 2014-11-06
Environment Health And Safety HIGH 7.5
CVE-2014-8664

SQL injection vulnerability in Product Safety (EHS-SAF) component in SAP Environment, Health, and Safety Management allows remote attackers to execut…

Mitigation only
Fix from $1,950 2014-11-06
Contract Accounting HIGH 7.5
CVE-2014-8668

SQL injection vulnerability in SAP Contract Accounting allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Document Management Services HIGH 7.2
CVE-2014-8660

SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-11-06
Environment Health And Safety MEDIUM 5.0
CVE-2014-8659

Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files via unspecified vectors.

Mitigation only
Fix from $1,600 2014-11-06