Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2014-3787
SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.
Netweaver
after 7.20
MEDIUM 5.0
CVE-2014-3129
The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted …
Netweaver Software Lifecycle Manager
Mitigation only
MEDIUM 5.0
CVE-2014-3133
SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o…
Netweaver Java Application Server
Mitigation only
HIGH 7.5
CVE-2014-2751
SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Print And Output Management
Mitigation only
HIGH 7.5
CVE-2014-2752
SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via u…
Business Object Processing Framework For Abap
Mitigation only
HIGH 7.5
CVE-2013-7362
An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors.
Ccms Agent
No fix yet
HIGH 7.5
CVE-2013-7363
Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensitive information, modify the …
Solution Manager
Mitigation only
HIGH 7.5
CVE-2013-7364
An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri…
Netweaver
Mitigation only
HIGH 7.5
CVE-2013-7367
SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via u…
Enterprise Portal
Mitigation only
HIGH 7.5
CVE-2014-2748
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes …
Enhancement Package
Mitigation only
MEDIUM 5.0
CVE-2013-7366
The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors relate…
Software Deployment Manager
No fix yet
MEDIUM 5.0
CVE-2014-2749
The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive inf…
Hana
Mitigation only
HIGH 7.5
CVE-2013-7355
SQL injection vulnerability in SAP BI Universal Data Integration allows remote attackers to execute arbitrary SQL commands via unspecified vectors, r…
Bi Universal Data Integration
No fix yet
HIGH 7.5
CVE-2013-7360
Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown vectors.
Adminadapter
Mitigation only
MEDIUM 5.0
CVE-2013-7356
Unspecified vulnerability in the SAP CCMS / Database Monitors for Oracle allows attackers to obtain the database password via unknown vectors.
Ccms \/ Database Monitor
No fix yet
MEDIUM 5.0
CVE-2013-7357
Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vector…
J2ee Engine
No fix yet
MEDIUM 5.0
CVE-2013-7358
Unspecified vulnerability in SAP Guided Procedures Archive Monitor allows remote attackers to obtain usernames, roles, profiles, and possibly other i…
Guided Procedures Archive Monitor
Mitigation only
MEDIUM 5.0
CVE-2013-7359
Unspecified vulnerability in SAP Mobile Infrastructure allows remote attackers to obtain sensitive port information via unknown vectors, related to a…
Mobile Infrastructure
No fix yet
MEDIUM 5.0
CVE-2013-7361
Directory traversal vulnerability in SAP CMS and CM Services allows attackers to upload arbitrary files via unspecified vectors.
Cm Services
Mitigation only
MEDIUM 5.0
CVE-2014-1960
The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecifie…
Netweaver
Mitigation only
MEDIUM 5.0
CVE-2014-1961
Unspecified vulnerability in the Portal WebDynPro in SAP NetWeaver allows remote attackers to obtain sensitive path information via unknown attack ve…
Netweaver
Mitigation only
MEDIUM 5.0
CVE-2014-1962
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE)…
Customer Relationship Management
Mitigation only
MEDIUM 5.0
CVE-2014-1963
Unspecified vulnerability in Message Server in SAP NetWeaver 7.20 allows remote attackers to cause a denial of service via unknown attack vectors.
Netweaver
No fix yet
HIGH 7.5
CVE-2013-7096
Multiple SQL injection vulnerabilities in SAP EMR Unwired allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Emr Unwired
No fix yet
HIGH 10.0
CVE-2013-7095
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML Exter…
Customer Relationship Management
Mitigation only
HIGH 7.5
CVE-2013-7094
SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands v…
Netweaver
Mitigation only
MEDIUM 5.0
CVE-2013-7093
SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vecto…
Network Interface Router
Mitigation only
HIGH 7.5
CVE-2013-6869
SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL comm…
Netweaver
Mitigation only
HIGH 10.0
CVE-2013-6822
GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue.
Netweaver
Mitigation only
MEDIUM 6.4
CVE-2013-6823
GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors.
Netweaver
No fix yet