Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2024-42372
Disclosure Date: November 12, 2024 (last updated November 12, 2024)
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2024-39593
Disclosure Date: July 09, 2024 (last updated August 30, 2024)
SAP Landscape Management allows an authenticated
user to read confidential data disclosed by the REST Provider Definition
response. Successful exploitation can cause high impact on confidentiality of
the managed entities.
0
Attacker Value
Unknown
CVE-2023-39245
Disclosure Date: February 15, 2024 (last updated January 24, 2025)
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
0
Attacker Value
Unknown
CVE-2023-39244
Disclosure Date: February 15, 2024 (last updated January 24, 2025)
DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level credentials.
0
Attacker Value
Unknown
CVE-2023-48772
Disclosure Date: December 18, 2023 (last updated December 22, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0.
0
Attacker Value
Unknown
CVE-2023-32551
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Landscape allowed URLs which caused open redirection.
0
Attacker Value
Unknown
CVE-2023-32550
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
0
Attacker Value
Unknown
CVE-2023-32549
Disclosure Date: June 06, 2023 (last updated October 08, 2023)
Landscape cryptographic keys were insecurely generated with a weak pseudo-random generator.
0
Attacker Value
Unknown
CVE-2023-26458
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems vulnerable to information disclosure and modification.The disclosed information is for Diagnostics Agent Connection via Java SCS Message Server of an SAP Solution Manager system and can only be accessed by authenticated SAP Landscape Management users, but they can escalate their privileges to the SAP Solution Manager system.
0
Attacker Value
Unknown
CVE-2021-38176
Disclosure Date: September 14, 2021 (last updated February 23, 2025)
Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain access to Backend Database. On successful exploitation the threat actor could completely compromise confidentiality, integrity, and availability of the system.
0