Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2017-16685
Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient…
Business Warehouse Universal Data Integration
Mitigation only
MEDIUM 5.3
CVE-2017-16687
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,…
Hana Database
Mitigation only
MEDIUM 6.1
CVE-2017-14516
Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292.
Businessobjects Financial Consolidation
Mitigation only
CRITICAL 9.8
CVE-2017-15295
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
Point Of Sale Xpress Server
Mitigation only
HIGH 8.8
CVE-2017-15296
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
Customer Relationship Management
No fix yet
HIGH 7.5
CVE-2017-15297
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
Host Agent
Mitigation only
CRITICAL 9.8
CVE-2017-15293
Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at…
Point Of Sale Xpress Server
Mitigation only
MEDIUM 6.1
CVE-2017-15294
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
Customer Relationship Management
Mitigation only
MEDIUM 6.1
CVE-2017-10701
Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Securi…
Enterprise Portal
after 7.50
HIGH 7.5
CVE-2017-14581
The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a craf…
Netweaver Application Server Java
after 7.50
HIGH 7.5
CVE-2017-14511
An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/…
E Recruiting
Mitigation only
CRITICAL 9.8
CVE-2015-7241EPSS 12%
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
Netweaver
after 7.0
HIGH 7.5
CVE-2014-8871
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlie…
Hybris
after 5.3.0.1
HIGH 7.5
CVE-2017-12637 KEVEPSS 95%
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2017-11459
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr…
Trex
Mitigation only
MEDIUM 6.5
CVE-2017-11457
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2017-11458
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.1
CVE-2017-11460
Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary …
Netweaver Portal
Mitigation only
HIGH 7.5
CVE-2017-9844EPSS 6%
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java…
Netweaver
Mitigation only
HIGH 7.5
CVE-2017-9845
disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG reque…
Netweaver
Mitigation only
MEDIUM 5.4
CVE-2017-9613
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web …
Successfactors
No fix yet
CRITICAL 9.6
CVE-2016-6256EPSS 8%
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell…
Business One
No fix yet
HIGH 8.8
CVE-2017-8913
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks…
Netweaver Application Server Java
Mitigation only
HIGH 8.3
CVE-2017-8914
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user …
Hana Xs
Mitigation only
HIGH 7.5
CVE-2017-8915
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing …
Hana Xs
Mitigation only
HIGH 7.8
CVE-2017-8852
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted r…
Sapcar
No fix yet
HIGH 8.8
CVE-2017-7717
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users…
Netweaver Application Server Java
Mitigation only
HIGH 7.5
CVE-2017-7696EPSS 36%
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in t…
Sso Authentication Library
Mitigation only
CRITICAL 9.8
CVE-2016-6818
SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify…
Business Intelligence Platform
Mitigation only
CRITICAL 9.8
CVE-2016-6143
SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.
Hana
Mitigation only