Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Internet Graphics Server HIGH 10.0
CVE-2006-6346

Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote att…

Fix: after 7.00_patch_3
Fix from $1,950 2006-12-07
Internet Graphics Server HIGH 7.5
CVE-2006-6345

Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows re…

Fix: after 7.00_patch_3
Fix from $1,950 2006-12-07
Sap Web Application Server MEDIUM 5.0
CVE-2006-6010EPSS 14%

SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceiv…

Mitigation only
Fix from $1,600 2006-11-21
Sap Web Application Server MEDIUM 5.0
CVE-2006-6011

Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers to cause a denial of service (enserver.exe crash)…

Mitigation only
Fix from $1,600 2006-11-21
Sap Web Application Server MEDIUM 5.0
CVE-2006-5785

Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2006-11-07
Internet Transaction Server MEDIUM 6.8
CVE-2006-5114

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject ar…

No fix yet
Fix from $1,600 2006-10-03
Internet Graphics Server HIGH 7.5
CVE-2006-4133EPSS 6%

Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial o…

Mitigation only
Fix from $1,950 2006-08-14
Internet Graphics Server MEDIUM 5.0
CVE-2006-4134

Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attac…

No fix yet
Fix from $1,600 2006-08-14
Sapdba HIGH 10.0
CVE-2006-2547

Unspecified vulnerability in the sapdba command in SAP with Informix before 700, and 700 up to patch 100, allows local users to execute arbitrary com…

Patch available
Fix from $1,950 2006-05-23
Sap Web Application Server MEDIUM 6.4
CVE-2006-1039

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive au…

Mitigation only
Fix from $1,600 2006-03-07
Business Connector MEDIUM 6.4
CVE-2006-0732

Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullNa…

Mitigation only
Fix from $1,600 2006-02-16
Sap R 3 HIGH 7.5
CVE-2005-4815

SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before…

Mitigation only
Fix from $1,950 2005-12-31
Sap Web Application Server MEDIUM 5.0
CVE-2005-3633

HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitra…

No fix yet
Fix from $1,600 2005-11-16
Sap Web Application Server MEDIUM 5.0
CVE-2005-3634EPSS 18%

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to a…

No fix yet
Fix from $1,600 2005-11-16
Sap R 3 MEDIUM 5.0
CVE-2005-1691

Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." se…

Fix: after 6.30
Fix from $1,600 2005-07-26
Sap R 3 HIGH 7.5
CVE-2002-1577

SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2…

Mitigation only
Fix from $1,950 2004-04-15
Sap R 3 HIGH 7.5
CVE-2002-1578

The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP …

Patch available
Fix from $1,950 2004-04-15
Sap R 3 HIGH 7.5
CVE-2003-1035

The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a b…

Mitigation only
Fix from $1,950 2004-04-15
Internet Transaction Server HIGH 7.5
CVE-2003-1036

Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long …

Fix: after 6.20_pl7
Fix from $1,950 2004-04-15
Internet Transaction Server HIGH 7.5
CVE-2003-1037

Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a …

Fix: after 6.20_pl7
Fix from $1,950 2004-04-15
Mysap Business Suite HIGH 7.5
CVE-2003-1039

Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) M…

Mitigation only
Fix from $1,950 2004-04-15
Sap Db HIGH 7.2
CVE-2002-1576

lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain pri…

Patch available
Fix from $1,950 2004-04-15
Sap Db HIGH 7.2
CVE-2003-1033

The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when …

Patch available
Fix from $1,950 2004-04-15
Sapgui MEDIUM 5.0
CVE-2002-1579

SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unkn…

Patch available
Fix from $1,600 2004-04-15
Internet Transaction Server MEDIUM 5.0
CVE-2003-1038

The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with a…

Fix: after 6.20_pl7
Fix from $1,600 2004-04-15
Sap Db HIGH 7.5
CVE-2003-0939

eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code vi…

Fix: after 7.4.03.27
Fix from $1,950 2003-12-15
Sap Db HIGH 7.5
CVE-2003-0941

web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct reque…

Fix: after 7.4.03.29
Fix from $1,950 2003-12-15
Sap Db HIGH 7.5
CVE-2003-0942

Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a …

Fix: after 7.4.03.29
Fix from $1,950 2003-12-15
Sap Db HIGH 7.5
CVE-2003-0943

web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially …

Fix: after 7.4.03.29
Fix from $1,950 2003-12-15
Sap Db HIGH 7.5
CVE-2003-0944

Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL wit…

Fix: after 7.4.03.29
Fix from $1,950 2003-12-15