Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Due to improper input validation in InfraBox, logs can be modified by an authenticated user. |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Aug 10, 2021 N/A· v4 6.1 MEDIUM· v3 2.6 LOW· v2 Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode URL parameters. An attacker can craft a malicious link and send it to a victim. A successful attack r...Show more |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Aug 10, 2021 N/A· v4 6.1 MEDIUM· v3 2.6 LOW· v2 Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode report data. An attacker can craft malicious data and print it to the report. In a...Show more |
Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or...Show more |
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects product...Show more |
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects pro...Show more |
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affec...Show more |
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830. |
The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681. |
The File RepositoRy Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to read arbitrary files via a full pathname, aka SAP Note 2018682. |
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905. |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Jul 14, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrit...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Jul 14, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver AS JAVA (Enterprise Portal), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50 reveals sensitive information in one of their HTTP requests, an attacker can use this in conjunction with other attacks such as XSS...Show more |
1Sap 2Netweaver Abap Netweaver Application Server AbapNov 21, 2024 Jul 14, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 8.04, 7.21, 7.21EXT, 7.22, 7.22EXT...Show more |
1Sap 2Internet Communication Manager Web DispatcherNov 21, 2024 Jul 14, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT,...Show more |
SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with basic level privileges to store a malicious scri...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds write and causes the application to crash and becoming temporarily unava...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes buffer overflow and causes the application to crash and becoming temporarily unavailab...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 7.5 HIGH· v2 A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code...Show more |
1Sap 2Netweaver Abap Netweaver Application Server AbapNov 21, 2024 Jul 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to external which can lead to information disclosure. |