Show filters
181 Total Results
Displaying 111-120 of 181
Sort by:
Attacker Value
Unknown
CVE-2021-27603
Disclosure Date: April 13, 2021 (last updated November 28, 2024)
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes thereby causing Denial of Service and affecting the Availability of the SAP system.
0
Attacker Value
Unknown
CVE-2021-27601
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attacker does not have control over kind or degree.
0
Attacker Value
Unknown
CVE-2021-21485
Disclosure Date: April 13, 2021 (last updated November 28, 2024)
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user.
0
Attacker Value
Unknown
CVE-2021-27598
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.
0
Attacker Value
Unknown
CVE-2021-21492
Disclosure Date: April 13, 2021 (last updated February 22, 2025)
SAP NetWeaver Application Server Java(HTTP Service), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate logon group in URLs, resulting in a content spoofing vulnerability when directory listing is enabled.
0
Attacker Value
Unknown
CVE-2021-21491
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
0
Attacker Value
Unknown
CVE-2021-21446
Disclosure Date: January 12, 2021 (last updated November 28, 2024)
SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.
0
Attacker Value
Unknown
CVE-2020-26829
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even outside the network segment dedicated for the internal cluster communication. As result, an unauthenticated attacker can invoke certain functions that would otherwise be restricted to system administrators only, including access to system administration functions or shutting down the system completely.
0
Attacker Value
Unknown
CVE-2020-26816
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded format and is not encrypted. This enables an attacker who has administrator access to the SAP NetWeaver AS Java to decode the keys because of missing encryption and get some application data and client credentials of adjacent systems. This highly impacts Confidentiality as information disclosed could contain client credentials of adjacent systems.
0
Attacker Value
Unknown
CVE-2020-26826
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upload.
0