Vulnerabilities > SAP > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-12 CVE-2019-0274 Unspecified vulnerability in SAP Mobile Platform SDK 3.0
SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service (i.e.
network
low complexity
sap
7.5
2019-03-12 CVE-2019-0270 Missing Authorization vulnerability in SAP products
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8
2019-03-12 CVE-2019-0268 XML Injection (aka Blind XPath Injection) vulnerability in SAP Businessobjects Business Intelligence 4.1/4.2/4.3
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.
network
low complexity
sap CWE-91
8.1
2019-02-15 CVE-2019-0267 Cross-Site Request Forgery (CSRF) vulnerability in SAP Manufacturing Integration and Intelligence 15.0/15.1/15.2
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens.
network
low complexity
sap CWE-352
8.8
2019-02-15 CVE-2019-0266 Information Exposure Through Log Files vulnerability in SAP Hana Extended Application Services 1.0
Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system.
network
low complexity
sap CWE-532
7.5
2019-02-15 CVE-2019-0258 Missing Authorization vulnerability in SAP Disclosure Management 10.01
SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8
2019-02-15 CVE-2019-0257 Missing Authorization vulnerability in SAP products
Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8
2019-02-15 CVE-2019-0255 Improper Input Validation vulnerability in SAP products
SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly.
network
low complexity
sap CWE-20
8.1
2019-01-08 CVE-2019-0249 Unspecified vulnerability in SAP Landscape Management 3.0
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
7.5
2019-01-08 CVE-2019-0243 Missing Authorization vulnerability in SAP Bw/4Hana 1.0
Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8