Lucene search

K

Sap Security Vulnerabilities

cve
cve

CVE-2020-6210

SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.

6.1CVSS

5.9AI Score

0.001EPSS

2020-03-10 09:15 PM
61
cve
cve

CVE-2020-6211

SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.

6.1CVSS

6.2AI Score

0.001EPSS

2020-04-14 08:15 PM
43
cve
cve

CVE-2020-6212

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user, allowing reading or modification...

5.4CVSS

5.4AI Score

0.001EPSS

2020-04-24 11:15 PM
81
cve
cve

CVE-2020-6213

SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_PHTMLB, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, is vulnerable to reflected Cross-Site Scripting (XSS) via different URL parameters as it does not sufficiently encode user controlled inputs.

6.1CVSS

5.9AI Score

0.001EPSS

2020-04-24 11:15 PM
93
cve
cve

CVE-2020-6214

SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploitation of the vulnerability would allow an authenticated attacker to view, change, or delete data, the...

4.7CVSS

4.7AI Score

0.001EPSS

2020-04-14 07:15 PM
17
cve
cve

CVE-2020-6215

SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerabilit...

6.1CVSS

6.1AI Score

0.002EPSS

2020-04-14 08:15 PM
52
cve
cve

CVE-2020-6216

SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

6.1CVSS

6AI Score

0.001EPSS

2020-04-14 07:15 PM
34
cve
cve

CVE-2020-6217

SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

6.1CVSS

5.9AI Score

0.001EPSS

2020-04-14 08:15 PM
35
cve
cve

CVE-2020-6218

Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information that should otherwise be restricted, leading to Information Disclosure.

5CVSS

5AI Score

0.001EPSS

2020-04-14 07:15 PM
33
cve
cve

CVE-2020-6219

SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service a...

8.8CVSS

8.6AI Score

0.001EPSS

2020-04-14 07:15 PM
34
cve
cve

CVE-2020-6220

BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.

4.7CVSS

4.6AI Score

0.001EPSS

2022-06-06 08:15 PM
32
5
cve
cve

CVE-2020-6221

Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

5.4CVSS

5.3AI Score

0.001EPSS

2020-04-14 07:15 PM
37
cve
cve

CVE-2020-6222

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

5.4CVSS

5.3AI Score

0.001EPSS

2020-04-14 07:15 PM
37
cve
cve

CVE-2020-6223

The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application, leading to Content Spoof...

6.1CVSS

6.1AI Score

0.001EPSS

2020-04-14 07:15 PM
27
cve
cve

CVE-2020-6224

SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure...

6.2CVSS

6.4AI Score

0.001EPSS

2020-04-14 07:15 PM
35
cve
cve

CVE-2020-6225

SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31, 7.40, 7.50), does not sufficiently validate path information provided by users, thus characters representing traverse to parent directory are passed through to the file APIs, al...

8.8CVSS

8.5AI Score

0.002EPSS

2020-04-14 08:15 PM
43
cve
cve

CVE-2020-6226

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

5.4CVSS

5.3AI Score

0.001EPSS

2020-04-14 07:15 PM
38
cve
cve

CVE-2020-6227

SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge additional entries in GLF log files.

7.5CVSS

7.4AI Score

0.001EPSS

2020-04-14 07:15 PM
30
cve
cve

CVE-2020-6228

SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer.

7.5CVSS

7.4AI Score

0.001EPSS

2020-04-14 07:15 PM
26
cve
cve

CVE-2020-6229

SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

6.1CVSS

5.9AI Score

0.001EPSS

2020-04-14 07:15 PM
23
cve
cve

CVE-2020-6230

SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application and lead to Code Injection. An attacker could thereby control the behavior of the application.

7.2CVSS

7AI Score

0.001EPSS

2020-04-14 07:15 PM
33
cve
cve

CVE-2020-6231

SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

5.4CVSS

5.3AI Score

0.001EPSS

2020-04-14 07:15 PM
31
cve
cve

CVE-2020-6232

SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.

5.3CVSS

5.3AI Score

0.001EPSS

2020-04-14 07:15 PM
23
cve
cve

CVE-2020-6233

SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system.

4.3CVSS

4.5AI Score

0.001EPSS

2020-04-14 07:15 PM
27
cve
cve

CVE-2020-6234

SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying operating system, leading to Privilege Escalation.

7.2CVSS

7.1AI Score

0.004EPSS

2020-04-14 07:15 PM
32
cve
cve

CVE-2020-6235

SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication.

8.6CVSS

8.6AI Score

0.002EPSS

2020-04-14 07:15 PM
32
cve
cve

CVE-2020-6236

SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a...

7.2CVSS

7.2AI Score

0.001EPSS

2020-04-14 07:15 PM
19
cve
cve

CVE-2020-6237

Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

7.5CVSS

7.3AI Score

0.002EPSS

2020-04-14 07:15 PM
24
cve
cve

CVE-2020-6238

SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.

9.3CVSS

9AI Score

0.003EPSS

2020-04-14 07:15 PM
29
cve
cve

CVE-2020-6239

Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.

4.4CVSS

4.7AI Score

0.0004EPSS

2020-06-10 01:15 PM
26
cve
cve

CVE-2020-6240

SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service

7.5CVSS

7.5AI Score

0.001EPSS

2020-05-12 06:15 PM
39
2
cve
cve

CVE-2020-6241

SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the system, leading to SQL Injection.

8.8CVSS

8.8AI Score

0.001EPSS

2020-05-12 06:15 PM
38
cve
cve

CVE-2020-6242

SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate, leading to Missing Aut...

9.8CVSS

9.4AI Score

0.007EPSS

2020-05-12 06:15 PM
37
cve
cve

CVE-2020-6243

Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure, allowing an attacker to read, modify, delete restricted data on connected ser...

8.8CVSS

8.5AI Score

0.001EPSS

2020-05-12 06:15 PM
39
cve
cve

CVE-2020-6244

SAP Business Client, version 7.0, allows an attacker after a successful social engineering attack to inject malicious code as a DLL file in untrusted directories that can be executed by the application, due to uncontrolled search path element. An attacker could thereby control the behavior of the a...

7.8CVSS

7.5AI Score

0.001EPSS

2020-05-12 06:15 PM
33
cve
cve

CVE-2020-6245

SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker with access to local instance, to inject file or code that can be executed by the application due to Improper Control of Resource Identifiers.

6.7CVSS

6.5AI Score

0.0004EPSS

2020-05-12 06:15 PM
31
cve
cve

CVE-2020-6246

SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.

6.1CVSS

5.9AI Score

0.001EPSS

2020-06-10 01:15 PM
19
cve
cve

CVE-2020-6247

SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a service. Using a specially crafted request, the attacker can crash or flood the Central Management Server, thereby impacting system availability.

7.5CVSS

7.5AI Score

0.001EPSS

2020-05-12 06:15 PM
34
cve
cve

CVE-2020-6248

SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.

7.2CVSS

7.8AI Score

0.001EPSS

2020-05-12 06:15 PM
37
cve
cve

CVE-2020-6249

The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.

8.8CVSS

8.8AI Score

0.001EPSS

2020-05-12 06:15 PM
43
cve
cve

CVE-2020-6250

SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read system administrator password leading to Information Disclosure. This could help the attacker to read/write any data and even stop the...

6.8CVSS

7AI Score

0.0004EPSS

2020-05-12 06:15 PM
37
cve
cve

CVE-2020-6251

Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted.

6.5CVSS

6.3AI Score

0.001EPSS

2020-05-12 06:15 PM
34
cve
cve

CVE-2020-6252

Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact syst...

8CVSS

7.8AI Score

0.0004EPSS

2020-05-12 06:15 PM
41
cve
cve

CVE-2020-6253

Under certain conditions, SAP Adaptive Server Enterprise (Web Services), versions 15.7, 16.0, allows an authenticated user to execute crafted database queries to elevate their privileges, modify database objects, or execute commands they are not otherwise authorized to execute, leading to SQL Injec...

7.2CVSS

7.7AI Score

0.001EPSS

2020-05-12 06:15 PM
33
cve
cve

CVE-2020-6254

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

6.1CVSS

5.9AI Score

0.001EPSS

2020-05-12 06:15 PM
33
cve
cve

CVE-2020-6256

SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check.

4.3CVSS

4.6AI Score

0.001EPSS

2020-05-12 06:15 PM
34
cve
cve

CVE-2020-6257

SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.

5.4CVSS

5.4AI Score

0.001EPSS

2020-05-12 06:15 PM
37
1
cve
cve

CVE-2020-6258

SAP Identity Management, version 8.0, does not perform necessary authorization checks for an authenticated user, allowing the attacker to view certain sensitive information of the victim, leading to Missing Authorization Check.

6.5CVSS

6.2AI Score

0.001EPSS

2020-05-12 06:15 PM
29
cve
cve

CVE-2020-6259

Under certain conditions SAP Adaptive Server Enterprise, versions 15.7, 16.0, allows an attacker to access information which would otherwise be restricted leading to Missing Authorization Check.

6.5CVSS

6.3AI Score

0.001EPSS

2020-05-12 06:15 PM
34
cve
cve

CVE-2020-6260

SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to inject superflous data that can be displayed by the application, due to Incomplete XML Validation. The application shows additional data that do not actually exist.

5.3CVSS

5.2AI Score

0.001EPSS

2020-06-10 01:15 PM
22
Total number of security vulnerabilities1433