Vulnerabilities > SAP > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-02-14 | CVE-2018-2378 | Unspecified vulnerability in SAP Hana Extended Application Services 1.0 In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption. | 6.5 |
2018-02-14 | CVE-2018-2377 | Unspecified vulnerability in SAP Hana Extended Application Services 1.0 In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users. | 6.5 |
2018-02-14 | CVE-2018-2374 | Unspecified vulnerability in SAP Hana Extended Application Services 1.0 In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space. | 6.5 |
2018-02-14 | CVE-2018-2372 | Information Exposure Through Log Files vulnerability in SAP Hana Extended Application Services 1.0 A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication. | 6.5 |
2018-02-14 | CVE-2018-2371 | Cross-site Scripting vulnerability in SAP Netweaver Java web Application 7.50 The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability. | 6.1 |
2018-02-14 | CVE-2018-2370 | Server-Side Request Forgery (SSRF) vulnerability in SAP BI Launchpad 4.10/4.20/4.30 Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user to use common techniques to determine which ports are in use on the backend server. | 5.3 |
2018-02-14 | CVE-2018-2369 | Unspecified vulnerability in SAP Hana 1.00/2.00 Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. | 5.3 |
2018-02-14 | CVE-2018-2364 | Cross-site Scripting vulnerability in SAP products SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability. | 6.1 |
2018-01-09 | CVE-2018-2362 | Unspecified vulnerability in SAP Hana 1.00/2.00 A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's hostname. | 5.3 |
2017-12-12 | CVE-2017-16691 | Improper Input Validation vulnerability in SAP Business Application Software Integrated Solution SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. | 6.5 |