Vulnerabilities > SAP > High

DATE CVE VULNERABILITY TITLE RISK
2016-10-13 CVE-2016-3946 Information Exposure vulnerability in SAP Sapconsole 7.30
SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note 2121461.
local
low complexity
sap CWE-200
7.8
2016-10-13 CVE-2016-3635 Improper Access Control vulnerability in SAP Netweaver 7.40
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.
network
high complexity
sap CWE-284
7.5
2016-10-05 CVE-2016-4551 Improper Access Control vulnerability in SAP Netweaver, SAP ABA and SAP Basis
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.
network
low complexity
sap CWE-284
7.5
2016-09-26 CVE-2016-6142 Unspecified vulnerability in SAP Hana 1.00.73.00.389160
SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.
network
low complexity
sap
7.5
2016-08-05 CVE-2016-6148 Improper Input Validation vulnerability in SAP Hana 1.00.73.00.389160
SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors related to an IMPORT statement, aka SAP Security Note 2233136.
network
low complexity
sap CWE-20
7.5
2016-08-05 CVE-2016-6144 Improper Access Control vulnerability in SAP Hana 1.0/1.00
The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is configured as "False," which makes it easier for remote attackers to bypass authentication via a brute force attack, aka SAP Security Note 2216869.
network
high complexity
sap CWE-284
8.1
2016-04-14 CVE-2016-4018 Improper Access Control vulnerability in SAP Hana
The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, gain privileges, and conduct unspecified other attacks via unspecified vectors, aka SAP Security Note 2262742.
network
low complexity
sap CWE-284
7.3
2016-04-14 CVE-2016-4017 Unspecified vulnerability in SAP Hana
The Data Provisioning Agent (aka DP Agent) in SAP HANA allows remote attackers to cause a denial of service (process crash) via unspecified vectors, aka SAP Security Note 2262710.
network
low complexity
sap
7.5
2016-04-14 CVE-2016-4015 Unspecified vulnerability in SAP Netweaver
The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.
network
low complexity
sap
7.5
2016-04-14 CVE-2016-4014 Unspecified vulnerability in SAP Netweaver 7.4
XML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of service (system hang) via a crafted DTD in an XML request to uddi/api/replication, aka SAP Security Note 2254389.
network
low complexity
sap
8.6