Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2020-6236

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation.
Attacker Value
Unknown

CVE-2020-6192

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.
Attacker Value
Unknown

CVE-2020-6191

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.
Attacker Value
Unknown

CVE-2019-0380

Disclosure Date: October 08, 2019 (last updated November 27, 2024)
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
Attacker Value
Unknown

CVE-2019-0261

Disclosure Date: February 15, 2019 (last updated November 27, 2024)
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)).
0
Attacker Value
Unknown

CVE-2019-0249

Disclosure Date: January 08, 2019 (last updated November 27, 2024)
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown

CVE-2018-2368

Disclosure Date: March 01, 2018 (last updated November 26, 2024)
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
0
Attacker Value
Unknown

CVE-2010-2904

Disclosure Date: July 28, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp.
0