Show filters
1,715 Total Results
Displaying 101-110 of 1,715
Sort by:
Attacker Value
Unknown
CVE-2024-41733
Disclosure Date: August 13, 2024 (last updated September 13, 2024)
In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
0
Attacker Value
Unknown
CVE-2024-41732
Disclosure Date: August 13, 2024 (last updated September 12, 2024)
SAP NetWeaver Application Server ABAP allows
an unauthenticated attacker to craft a URL link that could bypass allowlist
controls. Depending on the web applications provided by this server, the
attacker might inject CSS code or links into the web application that could
allow the attacker to read or modify information. There is no impact on
availability of application.
0
Attacker Value
Unknown
CVE-2024-41731
Disclosure Date: August 13, 2024 (last updated December 10, 2024)
SAP BusinessObjects Business Intelligence
Platform allows an authenticated attacker to upload malicious code over the
network, that could be executed by the application. On successful exploitation,
the attacker can cause a low impact on the Integrity of the application.
0
Attacker Value
Unknown
CVE-2024-41730
Disclosure Date: August 13, 2024 (last updated September 13, 2024)
In SAP BusinessObjects Business Intelligence
Platform, if Single Signed On is enabled on Enterprise authentication, an
unauthorized user can get a logon token using a REST endpoint. The attacker can
fully compromise the system resulting in High impact on confidentiality,
integrity and availability.
0
Attacker Value
Unknown
CVE-2024-33005
Disclosure Date: August 13, 2024 (last updated September 13, 2024)
Due to the missing authorization checks in the
local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application
Server (ABAP and Java), and SAP Content Server can impersonate other users and
may perform some unintended actions. This could lead to a low impact on
confidentiality and a high impact on the integrity and availability of the
applications.
0
Attacker Value
Unknown
CVE-2024-33003
Disclosure Date: August 13, 2024 (last updated September 17, 2024)
Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile numbers, coupon codes, and voucher codes, to be included in
the request URL as query or path parameters. On successful exploitation, this
could lead to a High impact on confidentiality and integrity of the
application.
0
Attacker Value
Unknown
CVE-2024-28166
Disclosure Date: August 13, 2024 (last updated December 10, 2024)
SAP BusinessObjects Business Intelligence
Platform allows an authenticated attacker to upload malicious code over the
network, that could be executed by the application. On successful
exploitation, the attacker can cause a low impact on the Integrity of the
application.
0
Attacker Value
Unknown
CVE-2024-41961
Disclosure Date: August 01, 2024 (last updated August 02, 2024)
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an `eval` sink which executes the code. Fixed in commit 8bce00be93b95a6512ff68fe86bf9554e486bc02.
0
Attacker Value
Unknown
CVE-2024-41805
Disclosure Date: July 26, 2024 (last updated July 28, 2024)
Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious JavaScript in the context of a user’s browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft. Tracks version 2.7.1 is patched. No known complete workarounds are available.
0
Attacker Value
Unknown
CVE-2024-39600
Disclosure Date: July 09, 2024 (last updated January 23, 2025)
Under certain conditions, the memory of SAP GUI
for Windows contains the password used to log on to an SAP system, which might
allow an attacker to get hold of the password and impersonate the affected
user. As a result, it has a high impact on the confidentiality but there is no
impact on the integrity and availability.
0