Lucene search

K

SAP SE Security Vulnerabilities

cve
cve

CVE-2020-26829

SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication.....

10CVSS

9.6AI Score

0.005EPSS

2020-12-09 05:15 PM
32
2
cve
cve

CVE-2020-26832

SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 104, 105, allows a high privileged user to execute a RFC function module to...

7.6CVSS

7.8AI Score

0.012EPSS

2020-12-09 05:15 PM
28
5
cve
cve

CVE-2020-26826

Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File...

6.5CVSS

6.5AI Score

0.001EPSS

2020-12-09 05:15 PM
23
cve
cve

CVE-2020-26816

SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access....

4.5CVSS

5.2AI Score

0.0004EPSS

2020-12-09 05:15 PM
16
cve
cve

CVE-2020-26828

SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to enter formulas which can call external applications or execute scripts. The execution of a payload (script) on target...

6.4CVSS

6.5AI Score

0.001EPSS

2020-12-09 05:15 PM
58
cve
cve

CVE-2020-6317

In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sensitive is of limited utility and cannot be used to further access, modify or...

3.5CVSS

3.9AI Score

0.0004EPSS

2020-11-30 07:15 PM
24
cve
cve

CVE-2020-26825

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs,...

6.1CVSS

6AI Score

0.001EPSS

2020-11-13 03:15 PM
52
cve
cve

CVE-2020-6316

SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization...

4.3CVSS

4.6AI Score

0.001EPSS

2020-11-10 05:15 PM
19
cve
cve

CVE-2020-26821

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the...

10CVSS

9.3AI Score

0.001EPSS

2020-11-10 05:15 PM
19
cve
cve

CVE-2020-26824

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availability of the...

10CVSS

9.3AI Score

0.001EPSS

2020-11-10 05:15 PM
25
cve
cve

CVE-2020-26820

SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate...

7.2CVSS

7.2AI Score

0.005EPSS

2020-11-10 05:15 PM
35
cve
cve

CVE-2020-26822

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the...

10CVSS

9.3AI Score

0.001EPSS

2020-11-10 05:15 PM
24
cve
cve

CVE-2020-26819

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access...

8.8CVSS

8.4AI Score

0.001EPSS

2020-11-10 05:15 PM
21
cve
cve

CVE-2020-26823

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impact to the integrity and availability of the...

10CVSS

9.3AI Score

0.001EPSS

2020-11-10 05:15 PM
20
cve
cve

CVE-2020-26810

SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request can render the SAP...

7.5CVSS

7.5AI Score

0.001EPSS

2020-11-10 05:15 PM
19
cve
cve

CVE-2020-26814

SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be used to read messages processed by the module leading to Information...

4.9CVSS

5AI Score

0.001EPSS

2020-11-10 05:15 PM
16
cve
cve

CVE-2020-26808

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be...

7.2CVSS

7.8AI Score

0.066EPSS

2020-11-10 05:15 PM
25
2
cve
cve

CVE-2020-26809

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and...

5.3CVSS

5.2AI Score

0.001EPSS

2020-11-10 05:15 PM
29
cve
cve

CVE-2020-26815

SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external....

8.6CVSS

8.3AI Score

0.002EPSS

2020-11-10 05:15 PM
20
cve
cve

CVE-2020-26807

SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the...

3.3CVSS

4.2AI Score

0.0004EPSS

2020-11-10 05:15 PM
20
cve
cve

CVE-2020-26811

SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads to Server Side...

5.3CVSS

5.2AI Score

0.002EPSS

2020-11-10 05:15 PM
18
cve
cve

CVE-2020-26817

SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

7.8CVSS

7.5AI Score

0.001EPSS

2020-11-10 05:15 PM
18
cve
cve

CVE-2020-26818

SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization,...

8.8CVSS

8.2AI Score

0.001EPSS

2020-11-10 05:15 PM
23
cve
cve

CVE-2020-6362

SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to privilege escalation and violation in segregation of duties, which in turn...

6.5CVSS

6.6AI Score

0.001EPSS

2020-10-20 02:15 PM
19
cve
cve

CVE-2020-6308

SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which is otherwise not accessible externally. On successful exploitation, attacker.....

5.3CVSS

5.7AI Score

0.006EPSS

2020-10-20 02:15 PM
63
15
cve
cve

CVE-2020-6369

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest have not been changed by the administrator.This may impact the confidentiality of....

5.9CVSS

6AI Score

0.002EPSS

2020-10-20 02:15 PM
17
2
cve
cve

CVE-2020-6367

There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user to click on a malicious link. The end users browser has no way to know that...

6.1CVSS

6.1AI Score

0.001EPSS

2020-10-20 02:15 PM
19
cve
cve

CVE-2020-6370

SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)...

4.8CVSS

4.9AI Score

0.001EPSS

2020-10-20 02:15 PM
19
cve
cve

CVE-2020-6315

SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive information when the victim loads the malicious file into the VE viewer, leading to Information...

5.5CVSS

5.2AI Score

0.001EPSS

2020-10-20 02:15 PM
15
cve
cve

CVE-2020-6366

SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS level from the server and/or can execute a...

6.5CVSS

6.6AI Score

0.001EPSS

2020-10-20 02:15 PM
21
cve
cve

CVE-2020-6365

SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal credentials of the...

6.1CVSS

6.4AI Score

0.001EPSS

2020-10-15 03:15 AM
52
cve
cve

CVE-2020-6375

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due....

5.5CVSS

5.4AI Score

0.001EPSS

2020-10-15 02:15 AM
36
cve
cve

CVE-2020-6376

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to...

5.5CVSS

5.4AI Score

0.001EPSS

2020-10-15 02:15 AM
33
cve
cve

CVE-2020-6373

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

7.8CVSS

7.5AI Score

0.001EPSS

2020-10-15 02:15 AM
33
cve
cve

CVE-2020-6372

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

7.8CVSS

7.5AI Score

0.001EPSS

2020-10-15 02:15 AM
37
cve
cve

CVE-2020-6374

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper...

7.8CVSS

7.5AI Score

0.001EPSS

2020-10-15 02:15 AM
37
cve
cve

CVE-2020-6368

SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users, leading to...

5.4CVSS

5.5AI Score

0.001EPSS

2020-10-15 02:15 AM
39
cve
cve

CVE-2020-6364

SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentially gain control over the host running the CA Introscope Enterprise Manager,leading to Code...

10CVSS

9.5AI Score

0.008EPSS

2020-10-15 02:15 AM
62
cve
cve

CVE-2020-6272

SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited,...

5.4CVSS

5.2AI Score

0.001EPSS

2020-10-15 02:15 AM
43
cve
cve

CVE-2020-6363

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change their own passphrase, but this does not invalidate...

4.6CVSS

4.6AI Score

0.001EPSS

2020-10-15 02:15 AM
40
cve
cve

CVE-2020-6319

SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different symbols which are otherwise not allowed. On successful exploitation an attacker can steal...

6.1CVSS

6.3AI Score

0.001EPSS

2020-10-15 02:15 AM
37
cve
cve

CVE-2020-6323

SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both reflected immediately and also be persisted and returned in further access to the...

6.1CVSS

5.9AI Score

0.001EPSS

2020-10-15 02:15 AM
44
cve
cve

CVE-2020-6371

User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information...

4.3CVSS

4.5AI Score

0.001EPSS

2020-10-15 02:15 AM
42
2
cve
cve

CVE-2020-6359

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PLT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

4.3CVSS

4.5AI Score

0.005EPSS

2020-09-09 01:15 PM
16
2
cve
cve

CVE-2020-6355

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

4.3CVSS

4.5AI Score

0.005EPSS

2020-09-09 01:15 PM
27
8
cve
cve

CVE-2020-6357

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

4.3CVSS

4.5AI Score

0.005EPSS

2020-09-09 01:15 PM
18
2
cve
cve

CVE-2020-6354

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SKP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

4.3CVSS

4.5AI Score

0.005EPSS

2020-09-09 01:15 PM
16
8
cve
cve

CVE-2020-6356

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

4.3CVSS

4.5AI Score

0.005EPSS

2020-09-09 01:15 PM
20
7
cve
cve

CVE-2020-6361

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE files received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

4.3CVSS

4.5AI Score

0.005EPSS

2020-09-09 01:15 PM
19
2
cve
cve

CVE-2020-6358

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated FBX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input...

4.3CVSS

4.5AI Score

0.005EPSS

2020-09-09 01:15 PM
19
2
Total number of security vulnerabilities879