Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8665

The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.

Mitigation only
Fix from $1,600 2014-11-06
Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8666

The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain …

Mitigation only
Fix from $1,600 2014-11-06
Netweaver MEDIUM 5.0
CVE-2014-0995EPSS 10%

The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled recursion a…

Fix: after 7.01
Fix from $1,600 2014-11-06
Commoncryptolib HIGH 7.5
CVE-2014-8587

SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attacke…

Fix: after 8.4.29
Fix from $1,950 2014-11-04
Hana HIGH 7.5
CVE-2014-8588

SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL commands via unspecified vec…

Mitigation only
Fix from $1,950 2014-11-04
Network Interface Router MEDIUM 5.0
CVE-2014-8589

Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via cra…

Mitigation only
Fix from $1,600 2014-11-04
Netweaver MEDIUM 5.0
CVE-2014-8591

Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a deni…

No fix yet
Fix from $1,600 2014-11-04
Netweaver MEDIUM 5.0
CVE-2014-8592

Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process ter…

Mitigation only
Fix from $1,600 2014-11-04
Hana MEDIUM 6.0
CVE-2014-8313

Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via uns…

No fix yet
Fix from $1,600 2014-10-16
Businessobjects Explorer MEDIUM 5.0
CVE-2014-8315

polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allow…

Mitigation only
Fix from $1,600 2014-10-16
Businessobjects Explorer MEDIUM 5.0
CVE-2014-8316

XML External Entity (XXE) vulnerability in polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 allows remote attackers to read arbitrar…

No fix yet
Fix from $1,600 2014-10-16
Businessobjects HIGH 7.1
CVE-2014-8310

The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFact…

No fix yet
Fix from $1,950 2014-10-16
Businessobjects MEDIUM 5.0
CVE-2014-8309

SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depen…

Mitigation only
Fix from $1,600 2014-10-16
Netweaver MEDIUM 6.5
CVE-2014-6252

Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated …

Mitigation only
Fix from $1,600 2014-09-05
Crystal Reports MEDIUM 6.8
CVE-2014-5505

Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file.

Mitigation only
Fix from $1,600 2014-09-04
Crystal Reports MEDIUM 6.8
CVE-2014-5506

Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT fil…

Mitigation only
Fix from $1,600 2014-09-04
Solution Manager HIGH 7.5
CVE-2014-5175

The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a ve…

Mitigation only
Fix from $1,950 2014-07-31
Fi Manager Self Service MEDIUM 6.0
CVE-2014-5176

SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors.

No fix yet
Fix from $1,600 2014-07-31
Hana Extended Application Services MEDIUM 5.0
CVE-2014-5173

SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that w…

No fix yet
Fix from $1,600 2014-07-31
Supplier Relationship Management MEDIUM 5.8
CVE-2014-4159

Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbit…

No fix yet
Fix from $1,600 2014-06-13
Brazil MEDIUM 5.0
CVE-2014-4005

SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Oil Industry Solution Traders And Schedulers Workbench MEDIUM 5.0
CVE-2014-4006

The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain ac…

Mitigation only
Fix from $1,600 2014-06-09
Upgrade Tools MEDIUM 5.0
CVE-2014-4007

The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Web Services Tool MEDIUM 5.0
CVE-2014-4008

SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Computing Center Management System Monitoring MEDIUM 5.0
CVE-2014-4009

SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Transaction Data Pool MEDIUM 5.0
CVE-2014-4010

SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

No fix yet
Fix from $1,600 2014-06-09
Capacity Leveling MEDIUM 5.0
CVE-2014-4011

SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

No fix yet
Fix from $1,600 2014-06-09
Open Hub Service MEDIUM 5.0
CVE-2014-4012

SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

Mitigation only
Fix from $1,600 2014-06-09
Netweaver HIGH 7.5
CVE-2014-4003

The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system.

No fix yet
Fix from $1,950 2014-06-09
Project System MEDIUM 5.0
CVE-2014-4004

The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote …

No fix yet
Fix from $1,600 2014-06-09