Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netweaver MEDIUM 5.0
CVE-2013-6821

Directory traversal vulnerability in the Exportability Check Service in SAP NetWeaver allows remote attackers to read arbitrary files via unspecified…

Mitigation only
Fix from $1,600 2013-11-20
Netweaver Development Infrastructure HIGH 9.3
CVE-2013-6820

Unrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers to execute arbitrary code by up…

Mitigation only
Fix from $1,950 2013-11-20
Network Interface Router MEDIUM 6.8
CVE-2013-6817

Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrar…

Mitigation only
Fix from $1,600 2013-11-20
Netweaver Logviewer MEDIUM 6.4
CVE-2013-6818

SAP NetWeaver Logviewer 6.30, when running on Windows, allows remote attackers to bypass intended access restrictions via unspecified vectors.

No fix yet
Fix from $1,600 2013-11-20
Netweaver MEDIUM 5.8
CVE-2013-6814

The J2EE Engine in SAP NetWeaver 6.40, 7.02, and earlier allows remote attackers to redirect users to arbitrary web sites, conduct phishing attacks, …

Fix: after 7.02
Fix from $1,600 2013-11-20
Netweaver MEDIUM 5.0
CVE-2013-6815

The SHSTI_UPLOAD_XML function in the Application Server for ABAP (AS ABAP) in SAP NetWeaver 7.31 and earlier allows remote attackers to cause a denia…

Fix: after 7.31
Fix from $1,600 2013-11-20
Erp Central Component HIGH 7.5
CVE-2013-6284

Unspecified vulnerability in the Statutory Reporting for Insurance (FS_SR) component in the Financial Services module for SAP ERP Central Component (…

Mitigation only
Fix from $1,950 2013-10-26
Erp Central Component MEDIUM 6.0
CVE-2013-3244

Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (EC…

Mitigation only
Fix from $1,600 2013-10-24
Netweaver MEDIUM 5.0
CVE-2013-6244

The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to r…

Fix: after 7.31
Fix from $1,600 2013-10-24
Netweaver MEDIUM 5.0
CVE-2013-5751

Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary files via unspecified vectors.

No fix yet
Fix from $1,600 2013-09-16
Netweaver HIGH 7.5
CVE-2013-5723

SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD…

Mitigation only
Fix from $1,950 2013-09-12
Netweaver MEDIUM 5.0
CVE-2013-3319EPSS 20%

The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted S…

Mitigation only
Fix from $1,600 2013-08-16
Production Planning And Control MEDIUM 6.5
CVE-2013-3062

The CP_RC_TRANSACTION_CALL_BY_SET function in the Engineering Workbench component in SAP Production Planning and Control allows remote authenticated …

Mitigation only
Fix from $1,600 2013-05-01
Basis Communication Services MEDIUM 6.0
CVE-2013-3063

SAP BASIS Communication Services 4.6B through 7.30 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

No fix yet
Fix from $1,600 2013-05-01
Erp Central Component MEDIUM 6.5
CVE-2013-3061

The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the S…

Mitigation only
Fix from $1,600 2013-05-01
Graphical User Interface MEDIUM 6.9
CVE-2011-5154

Multiple untrusted search path vulnerabilities in (1) SAPGui.exe and (2) BExAnalyzer.exe in SAP GUI 6.4 through 7.2 allow local users to gain privile…

Mitigation only
Fix from $1,600 2012-09-06
Netweaver Abap HIGH 10.0
CVE-2012-4341EPSS 9%

Multiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and exe…

Mitigation only
Fix from $1,950 2012-08-15
Netweaver HIGH 9.3
CVE-2012-2611EPSS 42%

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EH…

No fix yet
Fix from $1,950 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remo…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote atta…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remo…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote a…

No fix yet
Fix from $1,600 2012-05-15
Netweaver MEDIUM 5.0
CVE-2012-1291

Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive in…

Mitigation only
Fix from $1,600 2012-02-23
Netweaver MEDIUM 5.0
CVE-2012-1292

Unspecified vulnerability in the MessagingSystem servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Messa…

Mitigation only
Fix from $1,600 2012-02-23
Crystal Reports HIGH 9.3
CVE-2010-2590EPSS 47%

Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 S…

No fix yet
Fix from $1,950 2010-12-22
Netweaver Business Client HIGH 9.3
CVE-2010-4556EPSS 6%

Stack-based buffer overflow in the SapThemeRepository ActiveX control (sapwdpcd.dll) in SAP NetWeaver Business Client allows remote attackers to exec…

Mitigation only
Fix from $1,950 2010-12-17
Businessobjects HIGH 9.0
CVE-2010-3983

CmcApp in SAP BusinessObjects Enterprise XI 3.2 allows remote authenticated users to gain privileges via vectors involving the Program Job Server and…

No fix yet
Fix from $1,950 2010-10-18
Businessobjects MEDIUM 5.0
CVE-2010-3979

Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid use…

No fix yet
Fix from $1,600 2010-10-18
Businessobjects MEDIUM 5.0
CVE-2010-3982

SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentia…

No fix yet
Fix from $1,600 2010-10-18