Vulnerabilities > SAP
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-14 | CVE-2019-0316 | Cross-site Scripting vulnerability in SAP Netweaver Process Integration SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the victim is tricked to click on those malicious links, resulting in reflected Cross Site Scripting vulnerability. | 4.8 |
2019-06-14 | CVE-2019-0303 | Cross-site Scripting vulnerability in SAP Businessobjects 4.2/4.3 SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appService.jsp is reflecting requested parameter errMsg into response content without sanitation. | 6.1 |
2019-06-12 | CVE-2019-0315 | Unspecified vulnerability in SAP Netweaver Process Integration Under certain conditions the PI Integration Builder Web UI of SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50 and SAP_XIPCK 7.10 to 7.11, 7.20, 7.30) allows an attacker to access passwords used in FTP channels leading to information disclosure. | 7.5 |
2019-06-12 | CVE-2019-0314 | Unspecified vulnerability in SAP Inventory Manager and Work Manager SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | 5.5 |
2019-06-12 | CVE-2019-0312 | Missing Authentication for Critical Function vulnerability in SAP Netweaver Process Integration Several web pages provided SAP NetWeaver Process Integration (versions: SAP_XIESR: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 and SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50) are not password protected. | 5.3 |
2019-06-12 | CVE-2019-0311 | Cross-site Scripting vulnerability in SAP R/3 Enterprise Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-controlled inputs, this makes it possible for an attacker to send unwanted scripts to the browser of the victim using unwanted input and execute malicious code there, resulting in Cross-Site Scripting (XSS) vulnerability. | 6.1 |
2019-06-12 | CVE-2019-0308 | Cross-site Scripting vulnerability in SAP E-Commerce An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection. | 6.8 |
2019-06-12 | CVE-2019-0307 | Missing Encryption of Sensitive Data vulnerability in SAP Solution Manager 7.2 Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. | 2.4 |
2019-06-12 | CVE-2019-0306 | Unspecified vulnerability in SAP Hana Extended Application Services 1.0 SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names. | 4.3 |
2019-06-12 | CVE-2019-0305 | Improper Restriction of Rendered UI Layers or Frames vulnerability in SAP Netweaver Process Integration Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability. | 4.3 |