Show filters
119 Total Results
Displaying 101-110 of 119
Sort by:
Attacker Value
Unknown
CVE-2018-2365
Disclosure Date: March 01, 2018 (last updated November 26, 2024)
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2018-2368
Disclosure Date: March 01, 2018 (last updated November 26, 2024)
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
0
Attacker Value
Unknown
CVE-2018-2363
Disclosure Date: January 09, 2018 (last updated November 26, 2024)
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.
0
Attacker Value
Unknown
CVE-2017-16682
Disclosure Date: December 12, 2017 (last updated November 26, 2024)
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.
0
Attacker Value
Unknown
CVE-2017-16678
Disclosure Date: December 12, 2017 (last updated November 26, 2024)
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.
0
Attacker Value
Unknown
CVE-2017-11458
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.
0
Attacker Value
Unknown
CVE-2016-10311
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.
0
Attacker Value
Unknown
CVE-2016-4015
Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The Enqueue Server in SAP NetWeaver JAVA AS 7.1 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted request, aka SAP Security Note 2258784.
0
Attacker Value
Unknown
CVE-2015-2812
Disclosure Date: April 01, 2015 (last updated October 05, 2023)
XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966.
0
Attacker Value
Unknown
CVE-2015-2811
Disclosure Date: April 01, 2015 (last updated October 05, 2023)
XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939.
0