Show filters
295 Total Results
Displaying 131-140 of 295
Sort by:
Attacker Value
Unknown
CVE-2016-3980
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted HTTP request, aka SAP Security Note 2259547.
0
Attacker Value
Unknown
CVE-2015-8840
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215.
0
Attacker Value
Unknown
CVE-2016-3976
Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
0
Attacker Value
Unknown
CVE-2016-3974
Disclosure Date: April 07, 2016 (last updated November 25, 2024)
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.
0
Attacker Value
Unknown
CVE-2016-3975
Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigation.testComponent.NavigationURLTester, aka SAP Security Note 2238375.
0
Attacker Value
Unknown
CVE-2016-3973
Disclosure Date: April 07, 2016 (last updated November 25, 2024)
The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~rtc~coll.appl.rtc~wd_chat/Chat#, pressing "Add users", and doing a search, aka SAP Security Note 2255990.
0
Attacker Value
Unknown
CVE-2016-2388
Disclosure Date: February 16, 2016 (last updated November 25, 2024)
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.
0
Attacker Value
Unknown
CVE-2016-2386
Disclosure Date: February 16, 2016 (last updated November 25, 2024)
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.
0
Attacker Value
Unknown
CVE-2015-5006
Disclosure Date: December 07, 2015 (last updated October 05, 2023)
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
0
Attacker Value
Unknown
CVE-2015-0192
Disclosure Date: July 02, 2015 (last updated October 05, 2023)
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
0