Vulnerabilities > SAP > Landscape Management
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-09 | CVE-2024-39593 | Unspecified vulnerability in SAP Landscape Management 3.0 SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. | 5.7 |
2023-04-11 | CVE-2023-26458 | Exposure of Resource to Wrong Sphere vulnerability in SAP Landscape Management 3.0 An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. | 8.7 |
2020-04-14 | CVE-2020-6236 | Improper Privilege Management vulnerability in SAP Adaptive Extensions and Landscape Management SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. | 7.2 |
2020-02-12 | CVE-2020-6192 | Improper Input Validation vulnerability in SAP Landscape Management 3.0 SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. | 7.2 |
2020-02-12 | CVE-2020-6191 | Improper Input Validation vulnerability in SAP Landscape Management 3.0 SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation. | 7.2 |
2019-10-08 | CVE-2019-0380 | Information Exposure Through Log Files vulnerability in SAP Landscape Management 3.0 Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure. | 4.9 |
2019-02-15 | CVE-2019-0261 | Missing Authentication for Critical Function vulnerability in SAP Landscape Management 3.0 Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. | 9.8 |
2019-01-08 | CVE-2019-0249 | Unspecified vulnerability in SAP Landscape Management 3.0 Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted. | 7.5 |