Vulnerabilities > SAP > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-12-11 CVE-2019-0399 Unspecified vulnerability in SAP Portfolio and Project Management
SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user to discover accounting information of the Projects in Project dashboard, leading to Information Disclosure.
network
low complexity
sap
6.5
2019-12-11 CVE-2019-0395 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence Platform
SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.
network
low complexity
sap CWE-79
5.4
2019-11-13 CVE-2019-0388 Authentication Bypass by Spoofing vulnerability in SAP UI
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
network
low complexity
sap CWE-290
5.3
2019-11-13 CVE-2019-0386 Missing Authorization vulnerability in SAP ERP Sales and S4Hana Sales
Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges.
network
low complexity
sap CWE-862
6.3
2019-11-13 CVE-2019-0393 SQL Injection vulnerability in SAP Quality Management
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.
network
low complexity
sap CWE-89
4.3
2019-11-13 CVE-2019-0391 Unspecified vulnerability in SAP Netweaver Application Server Java
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
4.3
2019-11-13 CVE-2019-0390 Information Exposure vulnerability in SAP Diagnostics Agent 7.2
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap CWE-200
4.3
2019-11-13 CVE-2019-0385 Cross-site Scripting vulnerability in SAP Enable NOW 10/1902
SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.5
2019-11-13 CVE-2019-0382 Cross-site Scripting vulnerability in SAP Businessobjects Business Intelligence Platform
A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2.
network
low complexity
sap CWE-79
5.4
2019-10-08 CVE-2019-0381 Files or Directories Accessible to External Parties vulnerability in SAP Dynamic Tier, SAP IQ and SQL Anywhere
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.
local
low complexity
sap CWE-552
5.5