Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-21478 SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. Web Dynpro Abap Mitigation only Fix from $1,6002021-02-09 HIGH 7.5 CVE-2021-21469 When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an e… Netweaver Master Data Management Mitigation only Fix from $1,9502021-01-12 MEDIUM 6.5 CVE-2021-21468 The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allow… Business Warehouse No fix yet Fix from $1,6002021-01-12 MEDIUM 6.5 CVE-2021-21471 In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints which are not intended to be… Cla Assistant 2.8.5+ Fix from $1,6002021-01-12 CRITICAL 9.9 CVE-2021-21465 The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker … Business Warehouse No fix yet Fix from $2,3002021-01-12 HIGH 8.8 CVE-2021-21453 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21454 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21455 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21456 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21457 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21458 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21459 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21460 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21461 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21462 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21463 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21466 SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to … Business Warehouse No fix yet Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21449 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21450 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21451 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SGI file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 8.8 CVE-2021-21452 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of… 3d Visual Enterprise Viewer Mitigation only Fix from $1,9502021-01-12 HIGH 7.5 CVE-2021-21446 SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a se… Netweaver Application Server Abap Mitigation only Fix from $1,9502021-01-12 MEDIUM 6.5 CVE-2021-21448 SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend systems in the client PCs memo… Graphical User Interface Mitigation only Fix from $1,6002021-01-12 MEDIUM 5.4 CVE-2021-21445 SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Conten… Commerce Cloud Mitigation only Fix from $1,6002021-01-12 MEDIUM 5.4 CVE-2021-21447 SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malicious JavaScript payload into t… Businessobjects Business Intelligence Mitigation only Fix from $1,6002021-01-12 CRITICAL 10.0 CVE-2020-26829 SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because… Netweaver Application Server Java Mitigation only Fix from $2,3002020-12-09 CRITICAL 9.6 CVE-2020-26831 SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal repor… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002020-12-09 CRITICAL 9.1 CVE-2020-26837 SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an e… Solution Manager No fix yet Fix from $2,3002020-12-09 CRITICAL 9.1 CVE-2020-26838 SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacke… Business Warehouse Mitigation only Fix from $2,3002020-12-09 HIGH 8.1 CVE-2020-26830 SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due … Solution Manager No fix yet Fix from $1,9502020-12-09