Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2015-3980
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecifie…
Customer Relationship Management
Mitigation only
HIGH 7.5
CVE-2015-3979
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka…
Customer Relationship Management
Mitigation only
MEDIUM 5.0
CVE-2015-2820
Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process termination) via a crafted reque…
Afaria
No fix yet
MEDIUM 5.0
CVE-2015-2819
SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.
Sql Anywhere
No fix yet
MEDIUM 5.0
CVE-2015-2818
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SA…
Mobile Platform
Mitigation only
MEDIUM 5.0
CVE-2015-2817
The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Secu…
Netweaver
No fix yet
HIGH 7.5
CVE-2015-2816
The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted req…
Afaria
No fix yet
MEDIUM 6.5
CVE-2015-2815
Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remo…
Netweaver
No fix yet
MEDIUM 6.4
CVE-2015-2814
SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which…
Clinical Task Tracker
Mitigation only
MEDIUM 5.0
CVE-2015-2812
XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests …
Netweaver Enterprise Portal
No fix yet
MEDIUM 5.0
CVE-2015-2813
XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP …
Mobile Platform
No fix yet
MEDIUM 5.0
CVE-2015-2811
XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intr…
Netweaver Enterprise Portal
No fix yet
MEDIUM 5.0
CVE-2015-2076
The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note …
Businessobjects Edge
No fix yet
MEDIUM 5.0
CVE-2015-2075
SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011…
Businessobjects Edge
No fix yet
HIGH 7.5
CVE-2015-1312
The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and p…
Enterprise Resource Planning
Mitigation only
HIGH 10.0
CVE-2015-1311
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 209890…
Hana Extended Application Services
Mitigation only
MEDIUM 5.0
CVE-2015-1309
XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers …
Netweaver Abap
after 7.31
MEDIUM 6.5
CVE-2014-9595
Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…
Sap Kernel
Mitigation only
MEDIUM 6.5
CVE-2014-9594
Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…
Sap Kernel
Mitigation only
HIGH 10.0
CVE-2014-9387
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORB…
Businessobjects
Mitigation only
HIGH 7.5
CVE-2014-9264
Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alia…
Sql Anywhere
Mitigation only
HIGH 9.0
CVE-2013-3678
Multiple unspecified vulnerabilities in SAP Governance, Risk, and Compliance (GRC) allow remote authenticated users to gain privileges and execute ar…
Governance Risk And Compliance
No fix yet
HIGH 10.0
CVE-2014-8661
The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.
Customer Relationship Management Internet Sales
Mitigation only
HIGH 10.0
CVE-2014-8669EPSS 5%
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
Customer Relationship Management
Mitigation only
HIGH 7.8
CVE-2014-8662
Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors related to session handling.
Payroll Process
No fix yet
HIGH 7.5
CVE-2014-8663
SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands …
Netweaver Business Warehouse
Mitigation only
HIGH 7.5
CVE-2014-8664
SQL injection vulnerability in Product Safety (EHS-SAF) component in SAP Environment, Health, and Safety Management allows remote attackers to execut…
Environment Health And Safety
Mitigation only
HIGH 7.5
CVE-2014-8668
SQL injection vulnerability in SAP Contract Accounting allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Contract Accounting
Mitigation only
HIGH 7.2
CVE-2014-8660
SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.
Document Management Services
Mitigation only
MEDIUM 5.0
CVE-2014-8659
Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files via unspecified vectors.
Environment Health And Safety
Mitigation only