Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Business Planning And Consolidation Nov 21, 2024 Aug 2, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure an...Show more |
1Sap 1Dynamic Authorization Management Nov 21, 2024 Jul 10, 2018 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs. |
1Sap 1Internet Graphics Server Nov 21, 2024 Jul 10, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will...Show more |
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prevent legitimate users from accessing a service, either by crashing or fl...Show more |
1Sap 1Internet Graphics Server Nov 21, 2024 Jul 10, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modif...Show more |
Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Jul 10, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 3Netweaver Ui InfraUser Interface TechnologyNov 21, 2024 Jul 10, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implemen...Show more |
SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.53) allows an attacker to prevent legitimate users...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Jul 10, 2018 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successfu...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Jul 10, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 2Businessobjects Business Intelligence Crystal ReportsNov 21, 2024 Jul 10, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. A...Show more |
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0...Show more |
Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be restricted. |
1Sap 4Hana Database UiUi5+1 moreNov 21, 2024 Jun 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected a...Show more |
1Sap 1Internet Transaction Server Nov 21, 2024 May 24, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product. |
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. |
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. |
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. |
1Sap 1Internet Graphics Server Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation. |