Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2018-03-01 CVE-2018-2365 Cross-site Scripting vulnerability in SAP Netweaver Portal
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2018-02-14 CVE-2018-2396 Unspecified vulnerability in SAP Internet Graphics Server
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service.
network
low complexity
sap
6.5
2018-02-14 CVE-2018-2395 Unspecified vulnerability in SAP Internet Graphics Server
Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.
network
low complexity
sap
8.8
2018-02-14 CVE-2018-2394 Unspecified vulnerability in SAP Internet Graphics Server
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.
network
low complexity
sap
6.5
2018-02-14 CVE-2018-2393 XXE vulnerability in SAP Internet Graphics Server
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
network
low complexity
sap CWE-611
7.5
2018-02-14 CVE-2018-2392 XXE vulnerability in SAP Internet Graphics Server
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
network
low complexity
sap CWE-611
7.5
2018-02-14 CVE-2018-2391 Unspecified vulnerability in SAP Internet Graphics Server
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS portwatcher service.
network
low complexity
sap
6.5
2018-02-14 CVE-2018-2390 Unspecified vulnerability in SAP Internet Graphics Server
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.
network
low complexity
sap
6.5
2018-02-14 CVE-2018-2389 Improper Encoding or Escaping of Output vulnerability in SAP Internet Graphics Server
Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
network
low complexity
sap CWE-116
5.7
2018-02-14 CVE-2018-2388 Cross-site Scripting vulnerability in SAP Internet Graphics Server
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
network
low complexity
sap CWE-79
6.1