Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2018-2383 Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53. Internet Graphics Server Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.1 CVE-2018-2388 Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53. Internet Graphics Server Mitigation only Fix from $1,6002018-02-14 MEDIUM 5.7 CVE-2018-2389 Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding importa… Internet Graphics Server Mitigation only Fix from $1,6002018-02-14 HIGH 8.8 CVE-2018-2381 SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.0… Erp Financials Information System Mitigation only Fix from $1,9502018-02-14 HIGH 8.1 CVE-2018-2375 In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application e… Hana Extended Application Services Mitigation only Fix from $1,9502018-02-14 HIGH 8.1 CVE-2018-2376 In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application e… Hana Extended Application Services Mitigation only Fix from $1,9502018-02-14 HIGH 7.5 CVE-2018-2373 Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that del… Hana Extended Application Services Mitigation only Fix from $1,9502018-02-14 MEDIUM 6.5 CVE-2018-2372 A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL… Hana Extended Application Services Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.5 CVE-2018-2374 In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive app… Hana Extended Application Services Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.5 CVE-2018-2377 In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users. Hana Extended Application Services Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.5 CVE-2018-2378 In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumpti… Hana Extended Application Services Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.5 CVE-2018-2379 In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a spe… Hana Extended Application Services Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.5 CVE-2018-2382 A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled … Internet Graphics Server Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.1 CVE-2018-2364 SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in C… Customer Relationship Management Webclient Ui Mitigation only Fix from $1,6002018-02-14 MEDIUM 6.1 CVE-2018-2371 The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in C… Netweaver Java Web Application Mitigation only Fix from $1,6002018-02-14 MEDIUM 5.3 CVE-2018-2369 Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attac… Hana Mitigation only Fix from $1,6002018-02-14 MEDIUM 5.3 CVE-2018-2370 Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, … Bi Launchpad Mitigation only Fix from $1,6002018-02-14 HIGH 8.8 CVE-2018-2361 In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required… Solution Manager Mitigation only Fix from $1,9502018-01-09 HIGH 8.8 CVE-2018-2363 SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrar… Netweaver after 7.52 Fix from $1,9502018-01-09 HIGH 7.5 CVE-2018-2360 SAP Startup Service, SAP KERNEL 7.45, 7.49, and 7.52, is missing an authentication check for functionalities that require user identity and cause con… Sap Kernel Mitigation only Fix from $1,9502018-01-09 MEDIUM 5.3 CVE-2018-2362 A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose informa… Hana Mitigation only Fix from $1,6002018-01-09 CRITICAL 9.8 CVE-2017-16684 SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, and 4.30, does not perform authentication checks for functionaliti… Business Intelligence Promotion Management Application Mitigation only Fix from $2,3002017-12-12 HIGH 8.8 CVE-2017-16689 A Trusted RFC connection in SAP KERNEL 32NUC, SAP KERNEL 32Unicode, SAP KERNEL 64NUC, SAP KERNEL 64Unicode 7.21, 7.21EXT, 7.22, 7.22EXT; SAP KERNEL f… Sap Kernel Mitigation only Fix from $1,9502017-12-12 HIGH 7.8 CVE-2017-16690 A malicious DLL preload attack possible on NwSapSetup and Installation self-extracting program for SAP Plant Connectivity 2.3 and 15.0. It is possibl… Plant Connectivity Mitigation only Fix from $1,9502017-12-12 HIGH 7.5 CVE-2017-16680 Two potential audit log injections in SAP HANA extended application services 1.0, advanced model: 1) Certain HTTP/REST endpoints of controller servic… Hana Extended Application Services Mitigation only Fix from $1,9502017-12-12 HIGH 7.2 CVE-2017-16682 SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administra… Netweaver Internet Transaction Server after 7.52 Fix from $1,9502017-12-12 MEDIUM 6.5 CVE-2017-16683 Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from acc… Businessobjects Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.5 CVE-2017-16691 SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note… Business Application Software Integrated Solution Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-16679 URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21… Sap Kernel Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-16681 Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controll… Business Intelligence Promotion Management Application Mitigation only Fix from $1,6002017-12-12