Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2021-33705 The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) … Netweaver Portal Patch available Fix from $1,9502021-09-15 HIGH 7.8 CVE-2021-33700 SAP Business One, version - 10.0, allows a local attacker with access to the victim's browser under certain circumstances, to login as the victim wit… Business One Patch available Fix from $1,9502021-09-15 HIGH 7.5 CVE-2021-33692 SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..'… Cloud Connector Patch available Fix from $1,9502021-09-15 MEDIUM 6.8 CVE-2021-33693 SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potenti… Cloud Connector Patch available Fix from $1,6002021-09-15 MEDIUM 6.1 CVE-2021-33691 NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) v… Netweaver Development Infrastructure Patch available Fix from $1,6002021-09-15 MEDIUM 6.1 CVE-2021-33697 Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an unauthenticated attacker to … Businessobjects Business Intelligence Patch available Fix from $1,6002021-09-15 MEDIUM 5.4 CVE-2021-33696 SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and the… Businessobjects Business Intelligence Patch available Fix from $1,6002021-09-15 HIGH 8.8 CVE-2021-38176 Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution… Landscape Transformation Mitigation only Fix from $1,9502021-09-14 HIGH 7.5 CVE-2021-38177 SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted ma… Commoncryptolib after 8.5.38 Fix from $1,9502021-09-14 MEDIUM 6.5 CVE-2021-38174 When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the application crashes and becom… 3d Visual Enterprise Viewer Mitigation only Fix from $1,6002021-09-14 MEDIUM 6.5 CVE-2021-38175 SAP Analysis for Microsoft Office - version 2.8, allows an attacker with high privileges to read sensitive data over the network, and gather or chang… Analysis For Microsoft Office Mitigation only Fix from $1,6002021-09-14 CRITICAL 9.8 CVE-2021-37535 SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization… Netweaver Application Server Java Mitigation only Fix from $2,3002021-09-14 CRITICAL 9.4 CVE-2021-38162 SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53… Web Dispatcher No fix yet Fix from $2,3002021-09-14 HIGH 8.8 CVE-2021-37531 SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-adminis… Netweaver Knowledge Management Xml Forms No fix yet Fix from $1,9502021-09-14 HIGH 8.8 CVE-2021-38163 KEVEPSS 36% SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user… Netweaver Mitigation only Fix from $1,9502021-09-14 MEDIUM 6.5 CVE-2021-38150 When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business … Business Client Mitigation only Fix from $1,6002021-09-14 MEDIUM 5.4 CVE-2021-38164 SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE … Erp Financial Accounting Mitigation only Fix from $1,6002021-09-14 MEDIUM 6.5 CVE-2021-33685 SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of t… Business One Mitigation only Fix from $1,6002021-09-14 MEDIUM 6.1 CVE-2021-33675 Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a… Contact Center Mitigation only Fix from $1,6002021-09-14 MEDIUM 5.4 CVE-2021-33679 The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while cre… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002021-09-14 MEDIUM 5.3 CVE-2021-33686 Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but… Business One No fix yet Fix from $1,6002021-09-14 CRITICAL 9.6 CVE-2021-33672 Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message… Contact Center Mitigation only Fix from $2,3002021-09-14 MEDIUM 6.1 CVE-2021-33673 Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an a… Contact Center Mitigation only Fix from $1,6002021-09-14 MEDIUM 6.1 CVE-2021-33674 Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a… Contact Center Mitigation only Fix from $1,6002021-09-14 MEDIUM 6.1 CVE-2021-33703 Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker ca… Netweaver Enterprise Portal No fix yet Fix from $1,6002021-08-10 MEDIUM 6.1 CVE-2021-33707 SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a… Netweaver Knowledge Management No fix yet Fix from $1,6002021-08-10 MEDIUM 6.5 CVE-2021-33699 Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml wit… Fiori Client Mitigation only Fix from $1,6002021-08-10 MEDIUM 6.1 CVE-2021-33702 Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data.… Netweaver Enterprise Portal No fix yet Fix from $1,6002021-08-10 CRITICAL 9.8 CVE-2014-9320 SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privilege… Businessobjects Edge Patch available Fix from $2,3002021-08-09 HIGH 7.5 CVE-2015-2073 The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname,… Businessobjects Edge No fix yet Fix from $1,9502021-08-09