Vulnerabilities > SAP > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-03-12 CVE-2019-0276 Incorrect Authorization vulnerability in SAP products
Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorization check for an authenticated user, potentially resulting in escalation of privileges.
network
low complexity
sap CWE-863
6.5
2019-03-12 CVE-2019-0274 Unspecified vulnerability in SAP Mobile Platform SDK 3.0
SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service (i.e.
network
low complexity
sap
5.0
2019-03-12 CVE-2019-0271 Improper Input Validation vulnerability in SAP products
ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability.
network
low complexity
sap CWE-20
4.0
2019-03-12 CVE-2019-0270 Missing Authorization vulnerability in SAP products
ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
6.5
2019-03-12 CVE-2019-0268 XML Injection (aka Blind XPath Injection) vulnerability in SAP Businessobjects Business Intelligence 4.1/4.2/4.3
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source.
network
low complexity
sap CWE-91
5.5
2019-02-15 CVE-2019-0267 Cross-Site Request Forgery (CSRF) vulnerability in SAP Manufacturing Integration and Intelligence 15.0/15.1/15.2
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens.
network
sap CWE-352
6.8
2019-02-15 CVE-2019-0266 Information Exposure Through Log Files vulnerability in SAP Hana Extended Application Services 1.0
Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system.
network
low complexity
sap CWE-532
5.0
2019-02-15 CVE-2019-0265 XXE vulnerability in SAP products
SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
network
low complexity
sap CWE-611
4.0
2019-02-15 CVE-2019-0258 Missing Authorization vulnerability in SAP Disclosure Management 10.01
SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
6.5
2019-02-15 CVE-2019-0255 Improper Input Validation vulnerability in SAP products
SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly.
network
low complexity
sap CWE-20
5.5