Lucene search

K

SAP Security Vulnerabilities

cve
cve

CVE-2020-6229

SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS)...

6.1CVSS

5.9AI Score

0.001EPSS

2020-04-14 07:15 PM
23
cve
cve

CVE-2020-6231

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)...

5.4CVSS

5.3AI Score

0.001EPSS

2020-04-14 07:15 PM
31
cve
cve

CVE-2020-6219

SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service.....

8.8CVSS

8.6AI Score

0.001EPSS

2020-04-14 07:15 PM
34
cve
cve

CVE-2020-6227

SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge additional entries in GLF log...

7.5CVSS

7.4AI Score

0.001EPSS

2020-04-14 07:15 PM
30
cve
cve

CVE-2020-6214

SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data,...

4.7CVSS

4.7AI Score

0.001EPSS

2020-04-14 07:15 PM
17
cve
cve

CVE-2019-18904

A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Public Cloud 15-SP1, SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux....

7.5CVSS

7.3AI Score

0.002EPSS

2020-04-03 07:15 AM
112
cve
cve

CVE-2020-6210

SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS)...

6.1CVSS

5.9AI Score

0.001EPSS

2020-03-10 09:15 PM
61
cve
cve

CVE-2020-6205

SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed...

6.1CVSS

6.2AI Score

0.001EPSS

2020-03-10 09:15 PM
53
cve
cve

CVE-2020-6206

SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request...

4.3CVSS

4.7AI Score

0.001EPSS

2020-03-10 09:15 PM
62
cve
cve

CVE-2020-6201

The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Reflected Cross Site...

6.1CVSS

6.2AI Score

0.001EPSS

2020-03-10 09:15 PM
61
2
cve
cve

CVE-2020-6204

The selection query in SAP Treasury and Risk Management (Transaction Management) (EA-FINSERV?versions 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) returns more records than it should be when selecting and displaying the contract number, leading to Missing...

4.3CVSS

4.6AI Score

0.001EPSS

2020-03-10 09:15 PM
57
cve
cve

CVE-2020-6199

The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103, 104; does not have any authorization check to it due to which an attacker without an authorization....

5.4CVSS

5.4AI Score

0.001EPSS

2020-03-10 09:15 PM
65
cve
cve

CVE-2020-6203

SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading...

9.1CVSS

8.9AI Score

0.003EPSS

2020-03-10 09:15 PM
61
cve
cve

CVE-2020-6207

SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution...

9.8CVSS

9.5AI Score

0.974EPSS

2020-03-10 09:15 PM
1074
In Wild
70
cve
cve

CVE-2020-6208

SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code...

8.2CVSS

8.3AI Score

0.006EPSS

2020-03-10 09:15 PM
55
cve
cve

CVE-2020-6200

The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular...

5.4CVSS

5.4AI Score

0.001EPSS

2020-03-10 09:15 PM
62
cve
cve

CVE-2020-6202

SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML...

7.2CVSS

7AI Score

0.001EPSS

2020-03-10 09:15 PM
50
cve
cve

CVE-2020-6209

SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization...

7.5CVSS

7.4AI Score

0.001EPSS

2020-03-10 09:15 PM
43
cve
cve

CVE-2020-6196

SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which he can block all the threads resulting in a Denial of...

7.5CVSS

7.4AI Score

0.001EPSS

2020-03-10 09:15 PM
43
cve
cve

CVE-2020-6198

SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing Authentication...

9.8CVSS

9.4AI Score

0.002EPSS

2020-03-10 09:15 PM
62
cve
cve

CVE-2020-6197

SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the...

3.3CVSS

4AI Score

0.0004EPSS

2020-03-10 09:15 PM
58
cve
cve

CVE-2020-6178

SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information...

5.4CVSS

5.4AI Score

0.001EPSS

2020-03-10 09:15 PM
58
cve
cve

CVE-2019-3695

A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Module for Development....

8.4CVSS

7.4AI Score

0.001EPSS

2020-03-03 11:15 AM
130
cve
cve

CVE-2019-3696

A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise...

8.4CVSS

6.9AI Score

0.0004EPSS

2020-03-03 11:15 AM
129
cve
cve

CVE-2020-6186

SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host Agent, leading to Denial of...

7.5CVSS

7.5AI Score

0.001EPSS

2020-02-12 08:15 PM
36
cve
cve

CVE-2020-6191

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input...

7.2CVSS

7AI Score

0.001EPSS

2020-02-12 08:15 PM
30
cve
cve

CVE-2020-6192

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape...

7.2CVSS

7.2AI Score

0.001EPSS

2020-02-12 08:15 PM
36
cve
cve

CVE-2020-6188

VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization...

8.8CVSS

8.5AI Score

0.001EPSS

2020-02-12 08:15 PM
34
cve
cve

CVE-2020-6185

Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting...

5.4CVSS

5.2AI Score

0.001EPSS

2020-02-12 08:15 PM
38
cve
cve

CVE-2020-6187

SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of...

4.9CVSS

5.1AI Score

0.001EPSS

2020-02-12 08:15 PM
38
cve
cve

CVE-2020-6190

Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information...

5.8CVSS

5.4AI Score

0.001EPSS

2020-02-12 08:15 PM
48
cve
cve

CVE-2020-6189

Certain settings page(s) in SAP Business Objects Business Intelligence Platform (CMC), version 4.2, generates error messages that can give enterprise private-network related information which would otherwise be restricted leading to Information...

5.3CVSS

5.1AI Score

0.001EPSS

2020-02-12 08:15 PM
48
cve
cve

CVE-2020-6193

SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS)...

6.1CVSS

6AI Score

0.001EPSS

2020-02-12 08:15 PM
37
cve
cve

CVE-2020-6184

Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS)...

6.1CVSS

6AI Score

0.001EPSS

2020-02-12 08:15 PM
38
cve
cve

CVE-2020-6183

SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user root privileges e.g. size of any directory, system hardware and OS details,...

6.5CVSS

6.4AI Score

0.001EPSS

2020-02-12 08:15 PM
36
cve
cve

CVE-2020-6181

Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP...

5.8CVSS

5.5AI Score

0.001EPSS

2020-02-12 08:15 PM
40
cve
cve

CVE-2020-6177

SAP Mobile Platform, version 3.0, does not sufficiently validate an XML document accepted from an untrusted source which could lead to partial denial of service. Since SAP Mobile Platform does not allow External-Entity resolving, there is no issue of leaking content of files on the...

4.3CVSS

4.5AI Score

0.001EPSS

2020-02-12 08:15 PM
38
cve
cve

CVE-2020-6306

Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and...

2.7CVSS

4.1AI Score

0.001EPSS

2020-01-14 06:15 PM
17
cve
cve

CVE-2020-6307

Automated Note Search Tool (update provided in SAP Basis 7.0, 7.01, 7.02, 7.31, 7.4, 7.5, 7.51, 7.52, 7.53 and 7.54) does not perform sufficient authorization checks leading to the reading of sensitive...

4.3CVSS

4.6AI Score

0.001EPSS

2020-01-14 06:15 PM
21
cve
cve

CVE-2020-6304

Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49 KERNEL 7.21, 7.49, 7.53) allows an attacker to prevent users from accessing its services through a....

7.5CVSS

7.3AI Score

0.001EPSS

2020-01-14 06:15 PM
20
cve
cve

CVE-2020-6305

PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)...

6.1CVSS

6AI Score

0.001EPSS

2020-01-14 06:15 PM
18
cve
cve

CVE-2020-6303

SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site...

5.4CVSS

5.5AI Score

0.001EPSS

2020-01-14 06:15 PM
18
cve
cve

CVE-2019-19906

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in...

7.5CVSS

7.5AI Score

0.005EPSS

2019-12-19 06:15 PM
259
cve
cve

CVE-2019-0384

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user...

8.8CVSS

8.6AI Score

0.001EPSS

2019-12-17 08:15 PM
25
cve
cve

CVE-2019-0383

Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of...

8.8CVSS

8.8AI Score

0.001EPSS

2019-12-17 08:15 PM
28
cve
cve

CVE-2019-0405

SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leading to a user enumeration vulnerability and Information...

7.5CVSS

7.3AI Score

0.002EPSS

2019-12-11 10:15 PM
44
cve
cve

CVE-2019-0404

SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information...

7.5CVSS

7.3AI Score

0.002EPSS

2019-12-11 10:15 PM
68
cve
cve

CVE-2019-0395

SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting...

5.4CVSS

5.4AI Score

0.001EPSS

2019-12-11 10:15 PM
48
cve
cve

CVE-2019-0398

Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web server, leading to Cross Site Request...

8.8CVSS

8.5AI Score

0.001EPSS

2019-12-11 10:15 PM
58
cve
cve

CVE-2019-0402

SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leading to Information...

4.4CVSS

4.6AI Score

0.0004EPSS

2019-12-11 10:15 PM
55
Total number of security vulnerabilities1150