Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2020-6290 SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session… Disclosure Management Mitigation only Fix from $1,6002020-07-14 MEDIUM 6.5 CVE-2020-6285 SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to… Netweaver Mitigation only Fix from $1,6002020-07-14 MEDIUM 6.1 CVE-2020-6276 SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-07-14 MEDIUM 6.1 CVE-2020-6281 SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting refle… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-07-14 MEDIUM 5.8 CVE-2020-6282 SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-… Netweaver Application Server Java Mitigation only Fix from $1,6002020-07-14 MEDIUM 5.4 CVE-2020-6267 Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag. Disclosure Management Mitigation only Fix from $1,6002020-07-14 MEDIUM 5.4 CVE-2020-6278 SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in th… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-07-14 MEDIUM 5.3 CVE-2020-6286EPSS 28% The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7… Netweaver Application Server Java Mitigation only Fix from $1,6002020-07-14 MEDIUM 5.3 CVE-2020-6261 SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validat… Solution Manager Mitigation only Fix from $1,6002020-07-01 CRITICAL 9.8 CVE-2020-6263 Standalone clients connecting to SAP NetWeaver AS Java via P4 Protocol, versions (SAP-JEECOR 7.00, 7.01; SERVERCOR 7.10, 7.11, 7.20, 7.30, 7.31, 7.40… Netweaver Application Server Java Mitigation only Fix from $2,3002020-06-10 CRITICAL 9.8 CVE-2020-6275 SAP Netweaver AS ABAP, versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, are vulnerable for Server Side Request Forgery Attac… Netweaver Application Server Abap Mitigation only Fix from $2,3002020-06-10 HIGH 8.2 CVE-2020-6271 SAP Solution Manager (Problem Context Manager), version 7.2, does not perform the necessary authentication, allowing an attacker to consume large amo… Solution Manager Mitigation only Fix from $1,9502020-06-10 HIGH 8.1 CVE-2020-6268 Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 10… Erp \(ea Finserv\) Mitigation only Fix from $1,9502020-06-10 HIGH 7.5 CVE-2020-6264 SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions which would otherwise be restric… Commerce Mitigation only Fix from $1,9502020-06-10 MEDIUM 6.5 CVE-2020-6269 Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would other… Businessobjects Business Intelligence Platform No fix yet Fix from $1,6002020-06-10 MEDIUM 6.5 CVE-2020-6270 SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization … Netweaver Application Server Abap Mitigation only Fix from $1,6002020-06-10 MEDIUM 5.4 CVE-2020-6266 SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation… Fiori Mitigation only Fix from $1,6002020-06-10 MEDIUM 6.1 CVE-2020-6246 SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not … Netweaver As Abap Business Server Pages Mitigation only Fix from $1,6002020-06-10 MEDIUM 5.3 CVE-2020-6260 SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to In… Solution Manager No fix yet Fix from $1,6002020-06-10 CRITICAL 9.8 CVE-2020-6265 SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authe… Commerce Mitigation only Fix from $2,3002020-06-09 HIGH 8.8 CVE-2020-6249 The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker … Master Data Governance \(s4core\) Mitigation only Fix from $1,9502020-05-12 HIGH 8.8 CVE-2020-6262 Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows … Application Server Mitigation only Fix from $1,9502020-05-12 HIGH 8.0 CVE-2020-6252 Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive an… Adaptive Server Enterprise Cockpit Mitigation only Fix from $1,9502020-05-12 HIGH 7.5 CVE-2020-6247 SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a ser… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502020-05-12 HIGH 7.2 CVE-2020-6248 SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while execut… Adaptive Server Enterprise Backup Server Mitigation only Fix from $1,9502020-05-12 HIGH 7.2 CVE-2020-6253 Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted databas… Adaptive Server Enterprise Mitigation only Fix from $1,9502020-05-12 MEDIUM 6.8 CVE-2020-6250 SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent n… Adaptive Server Enterprise Mitigation only Fix from $1,6002020-05-12 MEDIUM 6.7 CVE-2020-6245 SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can b… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-05-12 MEDIUM 6.5 CVE-2020-6251 Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access informatio… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002020-05-12 MEDIUM 6.5 CVE-2020-6258 SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certai… Identity Management Mitigation only Fix from $1,6002020-05-12