Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2017-16685 Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient… Business Warehouse Universal Data Integration Mitigation only Fix from $1,6002017-12-12 MEDIUM 5.3 CVE-2017-16687 The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00,… Hana Database Mitigation only Fix from $1,6002017-12-12 MEDIUM 6.1 CVE-2017-14516 Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292. Businessobjects Financial Consolidation Mitigation only Fix from $1,6002017-12-03 CRITICAL 9.8 CVE-2017-15295 Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064. Point Of Sale Xpress Server Mitigation only Fix from $2,3002017-10-16 HIGH 8.8 CVE-2017-15296 The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. Customer Relationship Management No fix yet Fix from $1,9502017-10-16 HIGH 7.5 CVE-2017-15297 SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993. Host Agent Mitigation only Fix from $1,9502017-10-16 CRITICAL 9.8 CVE-2017-15293 Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain at… Point Of Sale Xpress Server Mitigation only Fix from $2,3002017-10-16 MEDIUM 6.1 CVE-2017-15294 The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964. Customer Relationship Management Mitigation only Fix from $1,6002017-10-16 MEDIUM 6.1 CVE-2017-10701 Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Securi… Enterprise Portal after 7.50 Fix from $1,6002017-09-29 HIGH 7.5 CVE-2017-14581 The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a craf… Netweaver Application Server Java after 7.50 Fix from $1,9502017-09-19 HIGH 7.5 CVE-2017-14511 An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/… E Recruiting Mitigation only Fix from $1,9502017-09-17 CRITICAL 9.8 CVE-2015-7241EPSS 12% XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. Netweaver after 7.0 Fix from $2,3002017-09-06 HIGH 7.5 CVE-2014-8871 Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlie… Hybris after 5.3.0.1 Fix from $1,9502017-08-28 HIGH 7.5 CVE-2017-12637 KEVEPSS 95% Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote a… Netweaver Application Server Java Mitigation only Fix from $1,9502017-08-07 CRITICAL 9.8 CVE-2017-11459 SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitr… Trex Mitigation only Fix from $2,3002017-07-25 MEDIUM 6.5 CVE-2017-11457 XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o… Netweaver Application Server Java Mitigation only Fix from $1,6002017-07-25 MEDIUM 6.1 CVE-2017-11458 Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary… Netweaver Application Server Java Mitigation only Fix from $1,6002017-07-25 MEDIUM 6.1 CVE-2017-11460 Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary … Netweaver Portal Mitigation only Fix from $1,6002017-07-25 HIGH 7.5 CVE-2017-9844EPSS 6% SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java… Netweaver Mitigation only Fix from $1,9502017-07-12 HIGH 7.5 CVE-2017-9845 disp+work 7400.12.21.30308 in SAP NetWeaver 7.40 allows remote attackers to cause a denial of service (resource consumption) via a crafted DIAG reque… Netweaver Mitigation only Fix from $1,9502017-07-12 MEDIUM 5.4 CVE-2017-9613 Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web … Successfactors No fix yet Fix from $1,6002017-06-15 CRITICAL 9.6 CVE-2016-6256EPSS 8% SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell… Business One No fix yet Fix from $2,3002017-05-26 HIGH 8.8 CVE-2017-8913 The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks… Netweaver Application Server Java Mitigation only Fix from $1,9502017-05-23 HIGH 8.3 CVE-2017-8914 sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user … Hana Xs Mitigation only Fix from $1,9502017-05-23 HIGH 7.5 CVE-2017-8915 sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing … Hana Xs Mitigation only Fix from $1,9502017-05-23 HIGH 7.8 CVE-2017-8852 SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted r… Sapcar No fix yet Fix from $1,9502017-05-10 HIGH 8.8 CVE-2017-7717 SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users… Netweaver Application Server Java Mitigation only Fix from $1,9502017-04-14 HIGH 7.5 CVE-2017-7696EPSS 36% SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in t… Sso Authentication Library Mitigation only Fix from $1,9502017-04-14 CRITICAL 9.8 CVE-2016-6818 SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify… Business Intelligence Platform Mitigation only Fix from $2,3002017-04-13 CRITICAL 9.8 CVE-2016-6143 SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806. Hana Mitigation only Fix from $2,3002017-04-13