Vulnerabilities > SAP > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-06-12 CVE-2019-0311 Cross-site Scripting vulnerability in SAP R/3 Enterprise
Automotive Dealer Portal in SAP R/3 Enterprise Application (versions: 600, 602, 603, 604, 605, 606, 616, 617) does not sufficiently encode user-controlled inputs, this makes it possible for an attacker to send unwanted scripts to the browser of the victim using unwanted input and execute malicious code there, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2019-06-12 CVE-2019-0308 Cross-site Scripting vulnerability in SAP E-Commerce
An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different machine, leading to Code Injection.
network
low complexity
sap CWE-79
6.8
2019-06-12 CVE-2019-0306 Unspecified vulnerability in SAP Hana Extended Application Services 1.0
SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Platform users such as SpaceAuditors to execute requests to obtain a complete list of SAP HANA user IDs and names.
network
low complexity
sap
4.3
2019-06-12 CVE-2019-0305 Improper Restriction of Rendered UI Layers or Frames vulnerability in SAP Netweaver Process Integration
Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that belong to another application or domain, resulting in Clickjacking vulnerability.
network
low complexity
sap CWE-1021
4.3
2019-05-14 CVE-2019-0298 Cross-site Scripting vulnerability in SAP E-Commerce
SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
network
low complexity
sap CWE-79
6.1
2019-05-14 CVE-2019-0293 Missing Authorization vulnerability in SAP Solution Manager System 20081700/20081710/20081740
Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, before versions 2008_1_700, 2008_1_710, and 740).
network
low complexity
sap CWE-862
6.5
2019-05-14 CVE-2019-0291 Unspecified vulnerability in SAP Solution Manager 7.2
Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.
local
low complexity
sap
5.5
2019-04-10 CVE-2019-0284 XXE vulnerability in SAP Hana 1.0/2.0
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source.
local
low complexity
sap CWE-611
6.0
2019-04-10 CVE-2019-0282 Improper Authentication vulnerability in SAP Netweaver Process Integration
Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like release information, Java package and Java object names which can be misused by the attacker.
network
low complexity
sap CWE-287
5.3
2019-04-10 CVE-2019-0278 Unspecified vulnerability in SAP Netweaver Process Integration
Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database tables used by the application, leading to information disclosure.
network
low complexity
sap
4.3