Vulnerabilities > SAP > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-13 CVE-2019-0396 Improper Input Validation vulnerability in SAP Businessobjects Business Intelligence Platform 4.0/4.1
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source.
network
low complexity
sap CWE-20
5.5
2019-11-13 CVE-2019-0388 Authentication Bypass by Spoofing vulnerability in SAP UI
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.
network
low complexity
sap CWE-290
5.0
2019-11-13 CVE-2019-0386 Missing Authorization vulnerability in SAP ERP Sales and S4Hana Sales
Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges.
network
low complexity
sap CWE-862
6.5
2019-11-13 CVE-2019-0393 SQL Injection vulnerability in SAP Quality Management
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.
network
low complexity
sap CWE-89
4.0
2019-11-13 CVE-2019-0391 Unspecified vulnerability in SAP Netweaver Application Server Java
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap
4.0
2019-11-13 CVE-2019-0390 Information Exposure vulnerability in SAP Diagnostics Agent 7.2
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted.
network
low complexity
sap CWE-200
4.0
2019-11-13 CVE-2019-0389 Unspecified vulnerability in SAP Netweaver Application Server Java
An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.
network
low complexity
sap
6.5
2019-11-04 CVE-2019-0350 Unspecified vulnerability in SAP Hana Database 1.00/2.00
SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service
network
low complexity
sap
5.0
2019-10-08 CVE-2019-0380 Information Exposure Through Log Files vulnerability in SAP Landscape Management 3.0
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
network
low complexity
sap CWE-532
4.0
2019-10-08 CVE-2019-0379 Insufficient Verification of Data Authenticity vulnerability in SAP Process Integration 1.0/2.0
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authentication Check
network
low complexity
sap CWE-345
5.0