Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2013-1592EPSS 24% A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Serv… Netweaver No fix yet Fix from $2,3002020-01-23 HIGH 7.5 CVE-2020-6304 Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL6… Netweaver Internet Communication Manager \(kernel\) Mitigation only Fix from $1,9502020-01-14 MEDIUM 6.1 CVE-2020-6305 PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, result… Process Integration Mitigation only Fix from $1,6002020-01-14 MEDIUM 5.4 CVE-2020-6303 SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting. Disclosure Management 10.1+ Fix from $1,6002020-01-14 HIGH 8.8 CVE-2019-0383 Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.… Enterprise Extension Financial Services Mitigation only Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-0384 Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.… Enterprise Extension Financial Services Mitigation only Fix from $1,9502019-12-17 HIGH 7.5 CVE-2019-0404 SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure. Enable Now 1911+ Fix from $1,9502019-12-11 HIGH 7.5 CVE-2019-0405 SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leadi… Enable Now 1911+ Fix from $1,9502019-12-11 CRITICAL 9.8 CVE-2019-0403 SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Comm… Enable Now 1911+ Fix from $2,3002019-12-11 HIGH 8.8 CVE-2019-0398 Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, m… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502019-12-11 MEDIUM 6.5 CVE-2019-0399 SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user … Portfolio And Project Management Mitigation only Fix from $1,6002019-12-11 MEDIUM 5.4 CVE-2019-0395 SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori… Businessobjects Business Intelligence Platform 4.2+ Fix from $1,6002019-12-11 HIGH 7.1 CVE-2019-0396 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently valida… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502019-11-13 MEDIUM 6.3 CVE-2019-0386 Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1… Erp Sales Mitigation only Fix from $1,6002019-11-13 MEDIUM 5.3 CVE-2019-0388 SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content d… Ui Mitigation only Fix from $1,6002019-11-13 HIGH 8.8 CVE-2019-0389 An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privile… Netweaver Application Server Java Mitigation only Fix from $1,9502019-11-13 MEDIUM 6.5 CVE-2019-0385 SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Enable Now 1908+ Fix from $1,6002019-11-13 MEDIUM 5.4 CVE-2019-0382 A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corre… Businessobjects Business Intelligence Platform 4.2+ Fix from $1,6002019-11-13 HIGH 7.5 CVE-2019-0350 SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP… Hana Database Mitigation only Fix from $1,9502019-11-04 MEDIUM 6.5 CVE-2019-0370 Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere wi… Financial Consolidation Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.5 CVE-2019-0381 A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can resul… Dynamic Tier Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0369 SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute … Financial Consolidation Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0374 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0375 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0376 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0377 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controll… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0378 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlle… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.3 CVE-2019-0379 SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security pro… Process Integration Mitigation only Fix from $1,6002019-10-08 MEDIUM 5.4 CVE-2019-0368 SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does… Customer Relationship Management Bbpcrm Mitigation only Fix from $1,6002019-10-08 HIGH 7.5 CVE-2019-0365 SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22… Sap Kernel Mitigation only Fix from $1,9502019-09-10