Show filters
119 Total Results
Displaying 101-110 of 119
Sort by:
Attacker Value
Unknown

CVE-2018-2365

Disclosure Date: March 01, 2018 (last updated November 26, 2024)
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown

CVE-2018-2368

Disclosure Date: March 01, 2018 (last updated November 26, 2024)
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
0
Attacker Value
Unknown

CVE-2018-2363

Disclosure Date: January 09, 2018 (last updated November 26, 2024)
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.
0
Attacker Value
Unknown

CVE-2017-16682

Disclosure Date: December 12, 2017 (last updated November 26, 2024)
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.
0
Attacker Value
Unknown

CVE-2017-16678

Disclosure Date: December 12, 2017 (last updated November 26, 2024)
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.
0
Attacker Value
Unknown

CVE-2017-11458

Disclosure Date: July 25, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.
Attacker Value
Unknown

CVE-2016-10311

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.
0
Attacker Value
Unknown

CVE-2016-4015

Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.
0
Attacker Value
Unknown

CVE-2015-2812

Disclosure Date: April 01, 2015 (last updated October 05, 2023)
XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966.
0
Attacker Value
Unknown

CVE-2015-2811

Disclosure Date: April 01, 2015 (last updated October 05, 2023)
XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939.
0