Vulnerabilities > SAP
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-10-16 | CVE-2017-15293 | Improper Authentication vulnerability in SAP Point of Sale Xpress Server 1020/1030 Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. | 9.8 |
2017-09-29 | CVE-2017-10701 | Cross-site Scripting vulnerability in SAP Enterprise Portal Cross site scripting (XSS) vulnerability in SAP Enterprise Portal 7.50 allows remote attackers to inject arbitrary web script or HTML, aka SAP Security Notes 2469860, 2471209, and 2488516. | 6.1 |
2017-09-19 | CVE-2017-14581 | Unspecified vulnerability in SAP Netweaver Application Server Java The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a crafted request, aka SAP Security Note 2389181. | 7.5 |
2017-09-17 | CVE-2017-14511 | Improper Input Validation vulnerability in SAP E-Recruiting An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. | 7.5 |
2017-09-06 | CVE-2015-7241 | XXE vulnerability in SAP Netweaver 4.0/6.4/7.0 XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. | 9.8 |
2017-08-28 | CVE-2014-8871 | Path Traversal vulnerability in SAP Hybris Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier. | 7.5 |
2017-08-07 | CVE-2017-12637 | Path Traversal vulnerability in SAP Netweaver Application Server Java 7.50 Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. | 7.5 |
2017-07-25 | CVE-2017-11460 | Cross-site Scripting vulnerability in SAP Netweaver Portal 7.4 Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary web script or HTML via the responsecode parameter to shp/shp_result.jsp, aka SAP Security Note 2308535. | 6.1 |
2017-07-25 | CVE-2017-11459 | Code Injection vulnerability in SAP Trex 7.10 SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592. | 9.8 |
2017-07-25 | CVE-2017-11458 | Cross-site Scripting vulnerability in SAP Netweaver Application Server Java 7.30 Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783. | 6.1 |