Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2020-6375
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted …
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 5.5
CVE-2020-6376
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources wh…
3d Visual Enterprise Viewer
Mitigation only
CRITICAL 10.0
CVE-2020-6364EPSS 6%
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a…
Introscope Enterprise Manager
Mitigation only
MEDIUM 6.1
CVE-2020-6319
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScri…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2020-6323
SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an…
Netweaver Enterprise Portal
Mitigation only
MEDIUM 5.4
CVE-2020-6272
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content …
Commerce Cloud
Mitigation only
MEDIUM 5.4
CVE-2020-6368
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modif…
Business Planning And Consolidation
Mitigation only
MEDIUM 6.5
CVE-2020-6311
Banking services from SAP 9.0 (Bank Analyzer), version - 500, and SAP S/4HANA for financial products subledger, version � 100, does not correctly per…
Bank Analyzer
Mitigation only
MEDIUM 6.1
CVE-2020-6324
SAP Netweaver AS ABAP(BSP Test Application sbspext_table), version-700,701,720,730,731,740,750,751,752,753,754,755, allows an unauthenticated attacke…
Netweaver As Abap Business Server Pages
Mitigation only
HIGH 8.1
CVE-2020-6320
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of …
Marketing
Mitigation only
HIGH 7.2
CVE-2020-6318EPSS 6%
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of thi…
Abap Platform
No fix yet
MEDIUM 6.5
CVE-2020-6321
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of…
3d Visual Enterprise Viewer
Mitigation only
MEDIUM 5.4
CVE-2020-6326
SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked…
Netweaver Knowledge Management
Mitigation only
HIGH 8.1
CVE-2020-6302
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacke…
Commerce
Mitigation only
MEDIUM 6.5
CVE-2020-6313
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2020-6283
SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad ht…
Fiori Launchpad
Mitigation only
MEDIUM 5.4
CVE-2020-6312
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrati…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 5.3
CVE-2020-6288
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface) allows an attacker with edit document rights to upload any file…
Businessobjects Business Intelligence Platform
Mitigation only
CRITICAL 9.1
CVE-2020-6294
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for fun…
Businessobjects Business Intelligence Platform
Mitigation only
HIGH 8.8
CVE-2020-6296
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject co…
Abap Platform
Mitigation only
HIGH 8.1
CVE-2020-6298
SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Marke…
Generic Market Data
Mitigation only
HIGH 8.1
CVE-2020-6301
SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify…
Hcm Travel Management
No fix yet
HIGH 7.8
CVE-2020-6295
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat…
Adaptive Server Enterprise
Mitigation only
HIGH 7.5
CVE-2020-6309
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authent…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.0
CVE-2020-6284
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to ina…
Netweaver Knowledge Management
Mitigation only
MEDIUM 6.5
CVE-2020-6293
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to ac…
Netweaver Knowledge Management
Mitigation only
CRITICAL 10.0
CVE-2020-6287 KEVEPSS 95%
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker…
Netweaver Application Server Java
Mitigation only
HIGH 8.8
CVE-2020-6289
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to brow…
Disclosure Management
Mitigation only
HIGH 8.8
CVE-2020-6291
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating o…
Disclosure Management
Mitigation only
HIGH 8.8
CVE-2020-6292
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expirati…
Disclosure Management
Mitigation only