Vulnerabilities > SAP > Enterprise Portal

DATE CVE VULNERABILITY TITLE RISK
2022-07-12 CVE-2022-35224 Cross-site Scripting vulnerability in SAP Enterprise Portal
SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2017-09-29 CVE-2017-10701 Cross-site Scripting vulnerability in SAP Enterprise Portal 7.50
Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Security Notes 2469860, 2471209, and 2488516.
network
sap CWE-79
4.3
2014-04-10 CVE-2013-7367 Permissions, Privileges, and Access Controls vulnerability in SAP Enterprise Portal
SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via unspecified vectors.
network
low complexity
sap CWE-264
7.5
2014-04-10 CVE-2013-7365 Cross-Site Scripting vulnerability in SAP Enterprise Portal
Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
sap CWE-79
4.3