Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-7691 A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592. Trex Mitigation only Fix from $2,3002017-04-11 CRITICAL 9.8 CVE-2016-10311 Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to t… Netweaver Mitigation only Fix from $2,3002017-04-10 MEDIUM 6.5 CVE-2016-10304 The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and ser… Netweaver Application Server Java Mitigation only Fix from $1,6002017-04-10 CRITICAL 9.8 CVE-2017-6950 SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, a… Gui For Windows Mitigation only Fix from $2,3002017-03-23 HIGH 7.5 CVE-2017-5997 The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash… Sap Kernel Mitigation only Fix from $1,9502017-02-15 HIGH 7.5 CVE-2016-10079EPSS 6% SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515. Saplpd after 7400.3.11.33 Fix from $1,9502017-02-01 HIGH 7.5 CVE-2017-5372 The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system informati… Netweaver No fix yet Fix from $1,9502017-01-23 MEDIUM 6.1 CVE-2016-6856 Cross-site scripting (XSS) vulnerability in the Inbox Search feature in Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attack… Hybris after 5.6.0.10 Fix from $1,6002016-12-31 MEDIUM 5.4 CVE-2016-6857 Cross-site scripting (XSS) vulnerability in the Create Catalogue feature in Hybris Management Console (HMC) in SAP Hybris before 5.2.0.13, 5.3.x befo… Hybris 5.2.0.13 / 5.3.0.11+ Fix from $1,6002016-12-31 MEDIUM 5.4 CVE-2016-6858 Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x bef… Hybris 5.0.4.11 / 5.1.0.11+ Fix from $1,6002016-12-31 HIGH 7.5 CVE-2016-10005 Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~t… Solution Manager No fix yet Fix from $1,9502016-12-19 MEDIUM 6.5 CVE-2016-9563 KEVEPSS 24% BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi… Netweaver Application Server Java Mitigation only Fix from $1,6002016-11-23 HIGH 7.5 CVE-2016-9562 SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the … Netweaver Application Server Java Mitigation only Fix from $1,9502016-11-23 MEDIUM 6.5 CVE-2016-4407 The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to imperson… Sapcryptolib Mitigation only Fix from $1,6002016-10-13 HIGH 7.8 CVE-2016-3946 SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note … Sapconsole Mitigation only Fix from $1,9502016-10-13 MEDIUM 5.5 CVE-2016-3638 SAP SLD Registration Program (aka SLDREG) allows local users to cause a denial of service (memory corruption and process termination) via a crafted H… Sld Registration No fix yet Fix from $1,6002016-10-13 HIGH 7.5 CVE-2016-3635 SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remot… Netweaver Mitigation only Fix from $1,9502016-10-13 CRITICAL 9.1 CVE-2016-7435 The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.… Netweaver Mitigation only Fix from $2,3002016-10-05 HIGH 7.5 CVE-2016-4551 The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to … Netweaver Mitigation only Fix from $1,9502016-10-05 MEDIUM 5.3 CVE-2016-6146 The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security No… Trex No fix yet Fix from $1,6002016-09-27 CRITICAL 9.8 CVE-2016-6137 An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security N… Trex No fix yet Fix from $2,3002016-09-27 HIGH 7.5 CVE-2016-6142 SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to th… Hana No fix yet Fix from $1,9502016-09-26 MEDIUM 5.8 CVE-2016-5847 SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted… Sapcar Archive Tool No fix yet Fix from $1,6002016-08-13 MEDIUM 5.5 CVE-2016-5845 SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (prog… Sapcar No fix yet Fix from $1,6002016-08-13 CRITICAL 9.8 CVE-2016-6150 The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended ac… Hana No fix yet Fix from $2,3002016-08-05 MEDIUM 5.5 CVE-2016-6149 SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Se… Hana Sps09 No fix yet Fix from $1,6002016-08-05 HIGH 7.5 CVE-2016-6148 SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors relate… Hana No fix yet Fix from $1,9502016-08-05 CRITICAL 9.8 CVE-2016-6147 An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified… Trex No fix yet Fix from $2,3002016-08-05 MEDIUM 5.3 CVE-2016-6145 The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username… Hana Db No fix yet Fix from $1,6002016-08-05 HIGH 8.1 CVE-2016-6144 The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_u… Hana after 1.00.73.00.389160 Fix from $1,9502016-08-05