Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.9
CVE-2021-27602
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are transl…
Commerce
Mitigation only
MEDIUM 6.5
CVE-2021-27603
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length …
Netweaver Application Server Abap
Mitigation only
MEDIUM 6.5
CVE-2021-27609
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData s…
Focused Run
Mitigation only
MEDIUM 5.4
CVE-2021-27600
SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parame…
Manufacturing Execution
Mitigation only
MEDIUM 5.4
CVE-2021-27601
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a…
Netweaver Application Server Java
Mitigation only
MEDIUM 5.3
CVE-2021-27598
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like produ…
Netweaver Application Server Java
Mitigation only
HIGH 8.3
CVE-2021-21482
SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the MDM Server subnet to find the …
Netweaver Master Data Management
Mitigation only
MEDIUM 6.5
CVE-2021-21485
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow …
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2021-21491
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attack…
Netweaver Application Server Java
Mitigation only
HIGH 7.8
CVE-2021-27585
When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer versi…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27586
When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version …
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27587
When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, t…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27588
When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27589
When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27590
When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27591
When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version…
3d Visual Enterprise Viewer
Mitigation only
HIGH 7.8
CVE-2021-27592
When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes a…
3d Visual Enterprise Viewer
Mitigation only
HIGH 8.8
CVE-2021-21487
SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Payment Engine
Mitigation only
MEDIUM 6.5
CVE-2021-21488
Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data w…
Netweaver Knowledge Management
Mitigation only
CRITICAL 9.8
CVE-2021-21484
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bi…
Hana
Mitigation only
HIGH 8.8
CVE-2021-21480EPSS 51%
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a r…
Manufacturing Integration And Intelligence
No fix yet
HIGH 8.8
CVE-2021-21481
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This…
Netweaver
Mitigation only
HIGH 8.8
CVE-2021-21486
SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authoriz…
Enterprise Financial Services
Mitigation only
CRITICAL 9.9
CVE-2021-21477EPSS 30%
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attack…
Commerce
Mitigation only
CRITICAL 9.1
CVE-2021-21479EPSS 10%
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the sys…
Scimono
0.0.19+
HIGH 8.8
CVE-2021-21472
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installati…
Software Provisioning Manager
Mitigation only
HIGH 7.5
CVE-2021-21475
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation …
Netweaver Master Data Management Server
Mitigation only
MEDIUM 6.5
CVE-2021-21474
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion is…
Hana Database
Mitigation only
MEDIUM 6.1
CVE-2021-21444
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 6.1
CVE-2021-21476
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a…
Ui5
1.38.49 / 1.52.49+