Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2018-2452 The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, result… Netweaver Application Server Java Mitigation only Fix from $1,6002018-09-11 HIGH 8.6 CVE-2018-2449 SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid reposito… Supplier Relationship Management Mdm Catalog Mitigation only Fix from $1,9502018-08-14 HIGH 7.5 CVE-2018-2446 Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name… Businessobjects Business Intelligence Mitigation only Fix from $1,9502018-08-14 HIGH 7.2 CVE-2018-2450 SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore re… Maxdb Mitigation only Fix from $1,9502018-08-14 MEDIUM 6.6 CVE-2018-2451 XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentio… Hana Extended Application Services Patch available Fix from $1,6002018-08-14 MEDIUM 6.5 CVE-2018-2447 SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposi… Businessobjects Business Intelligence Mitigation only Fix from $1,6002018-08-14 MEDIUM 5.3 CVE-2018-2448 Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user exis… Supplier Relationship Management Mdm Catalog Mitigation only Fix from $1,6002018-08-14 CRITICAL 9.6 CVE-2018-2445 AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft… Businessobjects Business Intelligence Mitigation only Fix from $2,3002018-08-14 HIGH 8.8 CVE-2018-2442 In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session … Businessobjects Business Intelligence Mitigation only Fix from $1,9502018-08-14 MEDIUM 6.1 CVE-2018-2444 SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script… Businessobjects Financial Consolidation Mitigation only Fix from $1,6002018-08-14 MEDIUM 5.5 CVE-2018-2441 Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unico… Sap Kernel No fix yet Fix from $1,6002018-08-14 HIGH 8.1 CVE-2017-16349 An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e… Business Planning And Consolidation Mitigation only Fix from $1,9502018-08-02 CRITICAL 9.1 CVE-2018-2437 The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can l… Internet Graphics Server Mitigation only Fix from $2,3002018-07-10 HIGH 8.8 CVE-2018-2436 Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting i… R\/3 Enterprise Retail Mitigation only Fix from $1,9502018-07-10 HIGH 7.5 CVE-2018-2438 The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prev… Internet Graphics Server Mitigation only Fix from $1,9502018-07-10 MEDIUM 6.1 CVE-2018-2435 SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting … Netweaver Enterprise Portal after 7.02 Fix from $1,6002018-07-10 MEDIUM 5.9 CVE-2018-2439 The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is valid… Internet Graphics Server Mitigation only Fix from $1,6002018-07-10 HIGH 8.8 CVE-2018-2427 SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allow… Businessobjects Business Intelligence Patch available Fix from $1,9502018-07-10 HIGH 7.5 CVE-2018-2433 SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.2… Sap Kernel Mitigation only Fix from $1,9502018-07-10 MEDIUM 6.1 CVE-2018-2431 SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site… Businessobjects Business Intelligence Patch available Fix from $1,6002018-07-10 MEDIUM 5.4 CVE-2018-2432 SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include inv… Businessobjects Business Intelligence Patch available Fix from $1,6002018-07-10 HIGH 7.5 CVE-2018-2424 SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to th… Hana Database Mitigation only Fix from $1,9502018-06-12 MEDIUM 5.5 CVE-2018-2425 Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be r… Business One Mitigation only Fix from $1,6002018-06-12 MEDIUM 5.3 CVE-2018-2428 Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected a… Infrastructure Mitigation only Fix from $1,6002018-06-12 MEDIUM 6.1 CVE-2018-11415EPSS 8% SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indic… Internet Transaction Server No fix yet Fix from $1,6002018-05-24 HIGH 7.5 CVE-2018-2422 SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv… Internet Graphics Server Mitigation only Fix from $1,9502018-05-09 HIGH 7.5 CVE-2018-2423 SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from access… Internet Graphics Server Mitigation only Fix from $1,9502018-05-09 CRITICAL 9.8 CVE-2018-2418 SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could th… Maxdb Odbc Driver 7.9.09.07+ Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2018-2420 SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi… Internet Graphics Server Mitigation only Fix from $2,3002018-05-09 HIGH 7.5 CVE-2018-2421 SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv… Internet Graphics Server Mitigation only Fix from $1,9502018-05-09