Filtered by vendor Sap
Subscribe
Total
1304 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-8915 | 1 Sap | 1 Hana Xs | 2019-10-02 | 5.0 MEDIUM | 7.5 HIGH |
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694. | |||||
CVE-2018-2438 | 1 Sap | 1 Internet Graphics Server | 2019-10-02 | 5.0 MEDIUM | 7.5 HIGH |
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | |||||
CVE-2018-2454 | 1 Sap | 1 Enterprise Financial Services | 2019-10-02 | 6.5 MEDIUM | 8.8 HIGH |
SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |||||
CVE-2018-2455 | 1 Sap | 1 Enterprise Financial Services | 2019-10-02 | 6.5 MEDIUM | 8.8 HIGH |
SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |||||
CVE-2018-2485 | 1 Sap | 1 Fiori Client | 2019-10-02 | 6.4 MEDIUM | 7.7 HIGH |
It is possible for a malicious application or malware to execute JavaScript in a SAP Fiori application. This can include reading and writing of information and calling device specific JavaScript APIs in the application. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version. | |||||
CVE-2018-2489 | 1 Sap | 1 Fiori Client | 2019-10-02 | 6.8 MEDIUM | 7.8 HIGH |
Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version. | |||||
CVE-2018-2391 | 1 Sap | 1 Internet Graphics Server | 2019-10-02 | 4.0 MEDIUM | 6.5 MEDIUM |
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS portwatcher service. | |||||
CVE-2018-2361 | 1 Sap | 1 Solution Manager | 2019-10-02 | 6.5 MEDIUM | 8.8 HIGH |
In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools. | |||||
CVE-2018-2379 | 1 Sap | 1 Hana Extend Application Services | 2019-10-02 | 4.0 MEDIUM | 6.5 MEDIUM |
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint. | |||||
CVE-2018-2381 | 1 Sap | 1 Erp Financials Information System | 2019-10-02 | 6.5 MEDIUM | 8.8 HIGH |
SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | |||||
CVE-2018-2390 | 1 Sap | 1 Internet Graphics Server | 2019-10-02 | 4.0 MEDIUM | 6.5 MEDIUM |
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service. | |||||
CVE-2018-2394 | 1 Sap | 1 Internet Graphics Server | 2019-10-02 | 5.0 MEDIUM | 6.5 MEDIUM |
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files. | |||||
CVE-2018-2396 | 1 Sap | 1 Internet Graphics Server | 2019-10-02 | 4.0 MEDIUM | 6.5 MEDIUM |
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service. | |||||
CVE-2018-2494 | 1 Sap | 1 Business Application Software Integrated Solution | 2019-10-02 | 6.5 MEDIUM | 8.0 HIGH |
Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform. | |||||
CVE-2018-2490 | 1 Sap | 1 Fiori Client | 2019-10-02 | 6.8 MEDIUM | 7.8 HIGH |
The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version. | |||||
CVE-2018-2481 | 1 Sap | 1 Advanced Business Application Programming | 2019-10-02 | 6.5 MEDIUM | 7.2 HIGH |
In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a transaction code reserved for customer is used. By implementing such transaction code a malicious user may execute unauthorized transaction functionality. | |||||
CVE-2018-2461 | 1 Sap | 1 People Profile | 2019-10-02 | 6.5 MEDIUM | 8.8 HIGH |
Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges. | |||||
CVE-2018-2459 | 1 Sap | 1 Mobile Platform | 2019-10-02 | 5.0 MEDIUM | 7.5 HIGH |
Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occasionally receive some data values of a different user. | |||||
CVE-2019-0355 | 1 Sap | 1 Netweaver Application Server Java | 2019-09-11 | 6.5 MEDIUM | 7.2 HIGH |
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application. | |||||
CVE-2019-0361 | 1 Sap | 1 Supplier Relationship Management | 2019-09-11 | 4.3 MEDIUM | 6.1 MEDIUM |
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |