Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2018-2452
The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, result…
Netweaver Application Server Java
Mitigation only
HIGH 8.6
CVE-2018-2449
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid reposito…
Supplier Relationship Management Mdm Catalog
Mitigation only
HIGH 7.5
CVE-2018-2446
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name…
Businessobjects Business Intelligence
Mitigation only
HIGH 7.2
CVE-2018-2450
SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore re…
Maxdb
Mitigation only
MEDIUM 6.6
CVE-2018-2451
XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentio…
Hana Extended Application Services
Patch available
MEDIUM 6.5
CVE-2018-2447
SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposi…
Businessobjects Business Intelligence
Mitigation only
MEDIUM 5.3
CVE-2018-2448
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user exis…
Supplier Relationship Management Mdm Catalog
Mitigation only
CRITICAL 9.6
CVE-2018-2445
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send craft…
Businessobjects Business Intelligence
Mitigation only
HIGH 8.8
CVE-2018-2442
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session …
Businessobjects Business Intelligence
Mitigation only
MEDIUM 6.1
CVE-2018-2444
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script…
Businessobjects Financial Consolidation
Mitigation only
MEDIUM 5.5
CVE-2018-2441
Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unico…
Sap Kernel
No fix yet
HIGH 8.1
CVE-2017-16349
An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e…
Business Planning And Consolidation
Mitigation only
CRITICAL 9.1
CVE-2018-2437
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can l…
Internet Graphics Server
Mitigation only
HIGH 8.8
CVE-2018-2436
Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting i…
R\/3 Enterprise Retail
Mitigation only
HIGH 7.5
CVE-2018-2438
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prev…
Internet Graphics Server
Mitigation only
MEDIUM 6.1
CVE-2018-2435
SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting …
Netweaver Enterprise Portal
after 7.02
MEDIUM 5.9
CVE-2018-2439
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is valid…
Internet Graphics Server
Mitigation only
HIGH 8.8
CVE-2018-2427
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allow…
Businessobjects Business Intelligence
Patch available
HIGH 7.5
CVE-2018-2433
SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.2…
Sap Kernel
Mitigation only
MEDIUM 6.1
CVE-2018-2431
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site…
Businessobjects Business Intelligence
Patch available
MEDIUM 5.4
CVE-2018-2432
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include inv…
Businessobjects Business Intelligence
Patch available
HIGH 7.5
CVE-2018-2424
SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to th…
Hana Database
Mitigation only
MEDIUM 5.5
CVE-2018-2425
Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be r…
Business One
Mitigation only
MEDIUM 5.3
CVE-2018-2428
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected a…
Infrastructure
Mitigation only
MEDIUM 6.1
CVE-2018-11415EPSS 8%
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indic…
Internet Transaction Server
No fix yet
HIGH 7.5
CVE-2018-2422
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…
Internet Graphics Server
Mitigation only
HIGH 7.5
CVE-2018-2423
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from access…
Internet Graphics Server
Mitigation only
CRITICAL 9.8
CVE-2018-2418
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could th…
Maxdb Odbc Driver
7.9.09.07+
CRITICAL 9.8
CVE-2018-2420
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi…
Internet Graphics Server
Mitigation only
HIGH 7.5
CVE-2018-2421
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a serv…
Internet Graphics Server
Mitigation only