Vulnerabilities > SAP > Low

DATE CVE VULNERABILITY TITLE RISK
2018-04-10 CVE-2018-2410 Cross-site Scripting vulnerability in SAP Business ONE 9.2/9.3
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
network
sap CWE-79
3.5
2018-03-14 CVE-2018-2397 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence Platform
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
network
sap CWE-79
3.5
2018-03-14 CVE-2018-2402 Information Exposure vulnerability in SAP Hana 1.00/2.00
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system.
network
sap CWE-200
3.5
2017-07-25 CVE-2017-11458 Cross-site Scripting vulnerability in SAP Netweaver 7.3
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.
network
sap CWE-79
3.5
2017-07-12 CVE-2017-9843 Unspecified vulnerability in SAP Netweaver Abap 7.40
SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841.
network
low complexity
sap
2.7
2017-06-15 CVE-2017-9613 Cross-site Scripting vulnerability in SAP Successfactors
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web script or HTML via the file upload functionality.
network
sap CWE-79
3.5
2016-12-31 CVE-2016-6857 Cross-site Scripting vulnerability in SAP Hybris
Cross-site scripting (XSS) vulnerability in the Create Catalogue feature in Hybris Management Console (HMC) in SAP Hybris before 5.2.0.13, 5.3.x before 5.3.0.11, 5.4.x before 5.4.0.11, 5.5.0.x before 5.5.0.10, 5.5.1.x before 5.5.1.11, 5.6.x before 5.6.0.11, and 5.7.x before 5.7.0.15 allows remote authenticated users to inject arbitrary web script or HTML via the ID field.
network
sap CWE-79
3.5
2016-12-31 CVE-2016-6858 Cross-site Scripting vulnerability in SAP Hybris
Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x before 5.1.0.11, 5.1.1.x before 5.1.1.12, 5.2.0.x and 5.3.0.x before 5.3.0.10, 5.4.x before 5.4.0.9, 5.5.0.x before 5.5.0.9, 5.5.1.x before 5.5.1.10, 5.6.x before 5.6.0.8, and 5.7.x before 5.7.0.9 allows remote authenticated users to inject arbitrary web script or HTML via the Name field.
network
sap CWE-79
3.5
2016-12-14 CVE-2016-3684 Unspecified vulnerability in SAP Download Manager 1.1.3.0/2.1.142
SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of this key, aka SAP Security Note 2282338.
local
sap
1.9
2016-12-14 CVE-2016-3685 Use of Hard-coded Credentials vulnerability in SAP Download Manager 1.1.3.0/2.1.142
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP Security Note 2282338.
local
sap CWE-798
1.9