Vulnerabilities > SAP

DATE CVE VULNERABILITY TITLE RISK
2018-04-10 CVE-2018-2404 Unrestricted Upload of File with Dangerous Type vulnerability in SAP Disclosure Management 10.1
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
network
low complexity
sap CWE-434
7.5
2018-04-10 CVE-2018-2403 Unspecified vulnerability in SAP Disclosure Management 10.1
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
4.0
2018-03-14 CVE-2018-2402 Information Exposure vulnerability in SAP Hana 1.00/2.00
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system.
network
sap CWE-200
3.5
2018-03-14 CVE-2018-2399 Cross-site Scripting vulnerability in SAP Process Monitoring Infrastructure
Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs.
network
sap CWE-79
4.3
2018-03-14 CVE-2018-2398 Unspecified vulnerability in SAP Business Client 6.5
Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
5.0
2018-03-14 CVE-2018-2397 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence Platform
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
network
sap CWE-79
3.5
2018-03-01 CVE-2018-2380 Path Traversal vulnerability in SAP Customer Relationship Management
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
network
low complexity
sap CWE-22
6.5
2018-03-01 CVE-2018-2368 Missing Authentication for Critical Function vulnerability in SAP Netweaver System Landscape Directory
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
network
low complexity
sap CWE-306
7.5
2018-03-01 CVE-2018-2367 Path Traversal vulnerability in SAP Business Application Software Integrated Solution
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
network
low complexity
sap CWE-22
6.5
2018-03-01 CVE-2018-2365 Cross-site Scripting vulnerability in SAP Netweaver Portal
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
sap CWE-79
4.3