Vulnerability index

Browse CVEs

1,328 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2006-6346 Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote att… Internet Graphics Server after 7.00_patch_3 Fix from $1,9502006-12-07 HIGH 7.5 CVE-2006-6345 Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows re… Internet Graphics Server after 7.00_patch_3 Fix from $1,9502006-12-07 MEDIUM 5.0 CVE-2006-6010EPSS 14% SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceiv… Sap Web Application Server Mitigation only Fix from $1,6002006-11-21 MEDIUM 5.0 CVE-2006-6011 Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers to cause a denial of service (enserver.exe crash)… Sap Web Application Server Mitigation only Fix from $1,6002006-11-21 MEDIUM 5.0 CVE-2006-5785 Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to cause a denial of s… Sap Web Application Server Patch available Fix from $1,6002006-11-07 MEDIUM 6.8 CVE-2006-5114 Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject ar… Internet Transaction Server No fix yet Fix from $1,6002006-10-03 HIGH 7.5 CVE-2006-4133EPSS 6% Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial o… Internet Graphics Server Mitigation only Fix from $1,9502006-08-14 MEDIUM 5.0 CVE-2006-4134 Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attac… Internet Graphics Server No fix yet Fix from $1,6002006-08-14 HIGH 10.0 CVE-2006-2547 Unspecified vulnerability in the sapdba command in SAP with Informix before 700, and 700 up to patch 100, allows local users to execute arbitrary com… Sapdba Patch available Fix from $1,9502006-05-23 MEDIUM 6.4 CVE-2006-1039 SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive au… Sap Web Application Server Mitigation only Fix from $1,6002006-03-07 MEDIUM 6.4 CVE-2006-0732 Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullNa… Business Connector Mitigation only Fix from $1,6002006-02-16 HIGH 7.5 CVE-2005-4815 SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before… Sap R 3 Mitigation only Fix from $1,9502005-12-31 MEDIUM 5.0 CVE-2005-3633 HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitra… Sap Web Application Server No fix yet Fix from $1,6002005-11-16 MEDIUM 5.0 CVE-2005-3634EPSS 18% frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to a… Sap Web Application Server No fix yet Fix from $1,6002005-11-16 MEDIUM 5.0 CVE-2005-1691 Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." se… Sap R 3 after 6.30 Fix from $1,6002005-07-26 HIGH 7.5 CVE-2002-1577 SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2… Sap R 3 Mitigation only Fix from $1,9502004-04-15 HIGH 7.5 CVE-2002-1578 The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP … Sap R 3 Patch available Fix from $1,9502004-04-15 HIGH 7.5 CVE-2003-1035 The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a b… Sap R 3 Mitigation only Fix from $1,9502004-04-15 HIGH 7.5 CVE-2003-1036 Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long … Internet Transaction Server after 6.20_pl7 Fix from $1,9502004-04-15 HIGH 7.5 CVE-2003-1037 Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a … Internet Transaction Server after 6.20_pl7 Fix from $1,9502004-04-15 HIGH 7.5 CVE-2003-1039 Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) M… Mysap Business Suite Mitigation only Fix from $1,9502004-04-15 HIGH 7.2 CVE-2002-1576 lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain pri… Sap Db Patch available Fix from $1,9502004-04-15 HIGH 7.2 CVE-2003-1033 The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when … Sap Db Patch available Fix from $1,9502004-04-15 MEDIUM 5.0 CVE-2002-1579 SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unkn… Sapgui Patch available Fix from $1,6002004-04-15 MEDIUM 5.0 CVE-2003-1038 The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with a… Internet Transaction Server after 6.20_pl7 Fix from $1,6002004-04-15 HIGH 7.5 CVE-2003-0939 eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code vi… Sap Db after 7.4.03.27 Fix from $1,9502003-12-15 HIGH 7.5 CVE-2003-0941 web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct reque… Sap Db after 7.4.03.29 Fix from $1,9502003-12-15 HIGH 7.5 CVE-2003-0942 Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a … Sap Db after 7.4.03.29 Fix from $1,9502003-12-15 HIGH 7.5 CVE-2003-0943 web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially … Sap Db after 7.4.03.29 Fix from $1,9502003-12-15 HIGH 7.5 CVE-2003-0944 Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL wit… Sap Db after 7.4.03.29 Fix from $1,9502003-12-15