Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2021-27602 SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are transl… Commerce Mitigation only Fix from $2,3002021-04-13 MEDIUM 6.5 CVE-2021-27603 An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length … Netweaver Application Server Abap Mitigation only Fix from $1,6002021-04-13 MEDIUM 6.5 CVE-2021-27609 SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData s… Focused Run Mitigation only Fix from $1,6002021-04-13 MEDIUM 5.4 CVE-2021-27600 SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parame… Manufacturing Execution Mitigation only Fix from $1,6002021-04-13 MEDIUM 5.4 CVE-2021-27601 SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a… Netweaver Application Server Java Mitigation only Fix from $1,6002021-04-13 MEDIUM 5.3 CVE-2021-27598 SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ… Netweaver Application Server Java Mitigation only Fix from $1,6002021-04-13 HIGH 8.3 CVE-2021-21482 SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the … Netweaver Master Data Management Mitigation only Fix from $1,9502021-04-13 MEDIUM 6.5 CVE-2021-21485 An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow … Netweaver Application Server Java Mitigation only Fix from $1,6002021-04-13 MEDIUM 6.1 CVE-2021-21491 SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attack… Netweaver Application Server Java Mitigation only Fix from $1,6002021-03-10 HIGH 7.8 CVE-2021-27585 When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer versi… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 7.8 CVE-2021-27586 When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version … 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 7.8 CVE-2021-27587 When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, t… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 7.8 CVE-2021-27588 When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 7.8 CVE-2021-27589 When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 7.8 CVE-2021-27590 When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 7.8 CVE-2021-27591 When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 7.8 CVE-2021-27592 When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes a… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-03-09 HIGH 8.8 CVE-2021-21487 SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Payment Engine Mitigation only Fix from $1,9502021-03-09 MEDIUM 6.5 CVE-2021-21488 Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w… Netweaver Knowledge Management Mitigation only Fix from $1,6002021-03-09 CRITICAL 9.8 CVE-2021-21484 LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi… Hana Mitigation only Fix from $2,3002021-03-09 HIGH 8.8 CVE-2021-21480EPSS 51% SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a r… Manufacturing Integration And Intelligence No fix yet Fix from $1,9502021-03-09 HIGH 8.8 CVE-2021-21481 The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This… Netweaver Mitigation only Fix from $1,9502021-03-09 HIGH 8.8 CVE-2021-21486 SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz… Enterprise Financial Services Mitigation only Fix from $1,9502021-03-09 CRITICAL 9.9 CVE-2021-21477EPSS 30% SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attack… Commerce Mitigation only Fix from $2,3002021-02-09 CRITICAL 9.1 CVE-2021-21479EPSS 10% In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the sys… Scimono 0.0.19+ Fix from $2,3002021-02-09 HIGH 8.8 CVE-2021-21472 SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installati… Software Provisioning Manager Mitigation only Fix from $1,9502021-02-09 HIGH 7.5 CVE-2021-21475 Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation … Netweaver Master Data Management Server Mitigation only Fix from $1,9502021-02-09 MEDIUM 6.5 CVE-2021-21474 SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion is… Hana Database Mitigation only Fix from $1,6002021-02-09 MEDIUM 6.1 CVE-2021-21444 SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be… Businessobjects Business Intelligence Mitigation only Fix from $1,6002021-02-09 MEDIUM 6.1 CVE-2021-21476 SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a… Ui5 1.38.49 / 1.52.49+ Fix from $1,6002021-02-09