Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Nov 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this v...Show more |
SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service |
1Sap 3Dynamic Tier Sap IqSql AnywhereNov 21, 2024 Oct 8, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of...Show more |
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure. |
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authenticatio...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the inpu...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows an attacker to save malicious scripts in t...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the export dialog...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs and allows execution of scripts in the chart title re...Show more |
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use crafted input to interfere with the structure of the surrounding query leading to XPath Injection. |
SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which allows an attacker to execute scripts by uploading files containing malicious scripts, leading to ref...Show more |
1Sap 2Customer Relationship Management Bbpcrm Customer Relationship Management S4crmNov 21, 2024 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Oct 8, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Auth...Show more |
1Sap 5Sap Kernel Sap Kernel Krnl32nucSap Kernel Krnl32uc+2 moreNov 21, 2024 Sep 10, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versions 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73 and KERNEL before versions 7.21, 7.49, 7.53, 7.73, 7.76...Show more |
1Sap 1Hana Extended Application Services Nov 21, 2024 Sep 10, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to enumerate open ports. |
1Sap 1Hana Extended Application Services Nov 21, 2024 Sep 10, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.0.118, to overload the server or retrieve information about internal network ports. |
1Sap 1Supplier Relationship Management Nov 21, 2024 Sep 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabi...Show more |
The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges. |