Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2018-05-24 CVE-2018-11415 Cross-site Scripting vulnerability in SAP Internet Transaction Server 6.20
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs.
network
low complexity
sap CWE-79
6.1
2018-05-09 CVE-2018-2423 Unspecified vulnerability in SAP Internet Graphics Server
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
network
low complexity
sap
7.5
2018-05-09 CVE-2018-2422 Unspecified vulnerability in SAP Internet Graphics Server
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
network
low complexity
sap
7.5
2018-05-09 CVE-2018-2421 Unspecified vulnerability in SAP Internet Graphics Server
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
network
low complexity
sap
7.5
2018-05-09 CVE-2018-2420 Unrestricted Upload of File with Dangerous Type vulnerability in SAP Internet Graphics Server
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
network
low complexity
sap CWE-434
critical
9.8
2018-05-09 CVE-2018-2419 Missing Authorization vulnerability in SAP Ea-Finserv, S4Core and Sapscore
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
4.6
2018-05-09 CVE-2018-2418 Code Injection vulnerability in SAP Maxdb Odbc Driver
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application.
network
low complexity
sap CWE-94
critical
9.8
2018-05-09 CVE-2018-2417 Unspecified vulnerability in SAP Identity Management 8.0
Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
5.3
2018-05-09 CVE-2018-2416 Improper Input Validation vulnerability in SAP Identity Management 7.2/8.0
SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
network
low complexity
sap CWE-20
5.4
2018-05-09 CVE-2018-2415 Encoding Error vulnerability in SAP products
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.
network
low complexity
sap CWE-172
4.7