Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2014-3787 SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors. Netweaver after 7.20 Fix from $1,6002014-05-19 MEDIUM 5.0 CVE-2014-3129 The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted … Netweaver Software Lifecycle Manager Mitigation only Fix from $1,6002014-04-30 MEDIUM 5.0 CVE-2014-3133 SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o… Netweaver Java Application Server Mitigation only Fix from $1,6002014-04-30 HIGH 7.5 CVE-2014-2751 SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. Print And Output Management Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2014-2752 SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via u… Business Object Processing Framework For Abap Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7362 An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors. Ccms Agent No fix yet Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7363 Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the … Solution Manager Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7364 An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri… Netweaver Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7367 SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via u… Enterprise Portal Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2014-2748 The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes … Enhancement Package Mitigation only Fix from $1,9502014-04-10 MEDIUM 5.0 CVE-2013-7366 The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors relate… Software Deployment Manager No fix yet Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2014-2749 The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive inf… Hana Mitigation only Fix from $1,6002014-04-10 HIGH 7.5 CVE-2013-7355 SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL commands via unspecified vectors, r… Bi Universal Data Integration No fix yet Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7360 Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown vectors. Adminadapter Mitigation only Fix from $1,9502014-04-10 MEDIUM 5.0 CVE-2013-7356 Unspecified vulnerability in the SAP CCMS / Database Monitors for Oracle allows attackers to obtain the database password via unknown vectors. Ccms \/ Database Monitor No fix yet Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2013-7357 Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vector… J2ee Engine No fix yet Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2013-7358 Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other i… Guided Procedures Archive Monitor Mitigation only Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2013-7359 Unspecified vulnerability in SAP Mobile Infrastructure allows remote attackers to obtain sensitive port information via unknown vectors, related to a… Mobile Infrastructure No fix yet Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2013-7361 Directory traversal vulnerability in SAP CMS and CM Services allows attackers to upload arbitrary files via unspecified vectors. Cm Services Mitigation only Fix from $1,6002014-04-10 MEDIUM 5.0 CVE-2014-1960 The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecifie… Netweaver Mitigation only Fix from $1,6002014-02-14 MEDIUM 5.0 CVE-2014-1961 Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack ve… Netweaver Mitigation only Fix from $1,6002014-02-14 MEDIUM 5.0 CVE-2014-1962 Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE)… Customer Relationship Management Mitigation only Fix from $1,6002014-02-14 MEDIUM 5.0 CVE-2014-1963 Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service via unknown attack vectors. Netweaver No fix yet Fix from $1,6002014-02-14 HIGH 7.5 CVE-2013-7096 Multiple SQL injection vulnerabilities in SAP EMR Unwired allow remote attackers to execute arbitrary SQL commands via unspecified vectors. Emr Unwired No fix yet Fix from $1,9502013-12-13 HIGH 10.0 CVE-2013-7095 The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML Exter… Customer Relationship Management Mitigation only Fix from $1,9502013-12-13 HIGH 7.5 CVE-2013-7094 SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands v… Netweaver Mitigation only Fix from $1,9502013-12-13 MEDIUM 5.0 CVE-2013-7093 SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vecto… Network Interface Router Mitigation only Fix from $1,6002013-12-13 HIGH 7.5 CVE-2013-6869 SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL comm… Netweaver Mitigation only Fix from $1,9502013-11-23 HIGH 10.0 CVE-2013-6822 GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue. Netweaver Mitigation only Fix from $1,9502013-11-20 MEDIUM 6.4 CVE-2013-6823 GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors. Netweaver No fix yet Fix from $1,6002013-11-20