Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2019-0363 Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server… Hana Extended Application Services 1.0.118+ Fix from $1,9502019-09-10 MEDIUM 6.7 CVE-2019-0357 The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges. Hana Mitigation only Fix from $1,6002019-09-10 MEDIUM 6.1 CVE-2019-0361 SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode us… Supplier Relationship Management Mitigation only Fix from $1,6002019-09-10 HIGH 7.5 CVE-2019-0352 In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) are cached, which leads to an… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502019-09-10 HIGH 7.2 CVE-2019-0355 SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6… Netweaver Application Server Java Mitigation only Fix from $1,9502019-09-10 HIGH 7.2 CVE-2019-0349 SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.… Advanced Business Application Programming Platform Kernel Mitigation only Fix from $1,9502019-08-14 CRITICAL 9.8 CVE-2019-0344 KEVEPSS 7% Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to ex… Commerce Cloud Mitigation only Fix from $2,3002019-08-14 CRITICAL 9.8 CVE-2019-0345 A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30… Netweaver Application Server Java Mitigation only Fix from $2,3002019-08-14 HIGH 8.8 CVE-2019-0341 The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the a… Enable Now Mitigation only Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-0343 SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject … Commerce Cloud Mitigation only Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-0351 A remote code execution vulnerability exists in the SAP NetWeaver UDDI Server (Services Registry), versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50. Becau… Netweaver Mitigation only Fix from $1,9502019-08-14 MEDIUM 6.5 CVE-2019-0346 Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.5 CVE-2019-0348 SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if th… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.1 CVE-2019-0337 Java Proxy Runtime of SAP NetWeaver Process Integration, versions 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled in… Netweaver Process Integration Mitigation only Fix from $1,6002019-08-14 MEDIUM 5.4 CVE-2019-0340 The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulner… Enable Now 1902+ Fix from $1,6002019-08-14 MEDIUM 5.3 CVE-2019-0338 During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set,… Gateway Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.5 CVE-2019-0333 In some situations, when a client cancels a query in SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.2, 4.3, the at… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.1 CVE-2019-0332 SAP BusinessObjects Business Intelligence Platform (Info View), versions 4.1, 4.2, 4.3, allows an attacker to give some payload for keyword in the se… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 6.1 CVE-2019-0335 Under certain conditions SAP BusinessObjects Business Intelligence Platform (Central Management Console), versions 4.1, 4.2, 4.3, allows an attacker … Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 5.4 CVE-2019-0334 When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it is possible to store a malici… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 MEDIUM 5.3 CVE-2019-0331 Under certain conditions, SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, allows an attacker to access sen… Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-08-14 CRITICAL 9.1 CVE-2019-0330 The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to … Diagnostics Agent Mitigation only Fix from $2,3002019-07-10 HIGH 7.2 CVE-2019-0327 SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.… Netweaver Application Server Java Mitigation only Fix from $1,9502019-07-10 HIGH 7.2 CVE-2019-0328 ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an attacker the execution of OS c… Netweaver Process Integration Mitigation only Fix from $1,9502019-07-10 MEDIUM 6.1 CVE-2019-0329 SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Information Steward Mitigation only Fix from $1,6002019-07-10 MEDIUM 6.1 CVE-2019-0326 SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not sufficiently encode user-controlled … Businessobjects Business Intelligence Mitigation only Fix from $1,6002019-07-10 HIGH 7.5 CVE-2019-0319 The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error message. An attac… Gateway No fix yet Fix from $1,9502019-07-10 HIGH 7.5 CVE-2019-0322 SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent l… Commerce Cloud Mitigation only Fix from $1,9502019-07-10 MEDIUM 6.1 CVE-2019-0281 SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-controlled inputs, resulting in C… Openui5 1.38.39 / 1.44.39+ Fix from $1,6002019-07-10 MEDIUM 6.1 CVE-2019-0321 ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip… Netweaver Application Server Abap Mitigation only Fix from $1,6002019-07-10