Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2020-04-14 CVE-2020-6221 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence Platform 4.1/4.2
Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
5.4
2020-04-14 CVE-2020-6219 Deserialization of Untrusted Data vulnerability in SAP products
SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and denial of service and unauthorized execution of arbitrary commands, leading to Deserialization of Untrusted Data.
network
low complexity
sap CWE-502
8.8
2020-04-14 CVE-2020-6218 Unspecified vulnerability in SAP Businessobjects Business Intelligence Platform 4.1/4.2
Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information that should otherwise be restricted, leading to Information Disclosure.
network
low complexity
sap
5.0
2020-04-14 CVE-2020-6216 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence Platform 4.2
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2020-04-14 CVE-2020-6214 Incorrect Authorization vulnerability in SAP S/4Hana 100
SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports.
network
low complexity
sap CWE-863
4.7
2020-03-10 CVE-2020-6210 Cross-site Scripting vulnerability in SAP Fiori Launchpad 753/754
SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2020-03-10 CVE-2020-6209 Missing Authorization vulnerability in SAP Disclosure Management 10.1
SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Check.
network
high complexity
sap CWE-862
7.5
2020-03-10 CVE-2020-6208 Use After Free vulnerability in SAP Crystal Reports 4.1/4.2
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the behaviour of the application, leading to Remote Code Execution.
local
low complexity
sap CWE-416
8.2
2020-03-10 CVE-2020-6207 Missing Authentication for Critical Function vulnerability in SAP Solution Manager 7.20
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
network
low complexity
sap CWE-306
critical
9.8
2020-03-10 CVE-2020-6206 Cross-Site Request Forgery (CSRF) vulnerability in SAP Cloud Platform Integration 1.0
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages.
network
low complexity
sap CWE-352
4.3