Show filters
181 Total Results
Displaying 141-150 of 181
Sort by:
Attacker Value
Unknown

CVE-2020-6202

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.
Attacker Value
Unknown

CVE-2015-7968

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
Attacker Value
Unknown

CVE-2020-6190

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.
Attacker Value
Unknown

CVE-2019-0389

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.
Attacker Value
Unknown

CVE-2019-0391

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
Attacker Value
Unknown

CVE-2019-0355

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
Attacker Value
Unknown

CVE-2019-0345

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request Forgery.
0
Attacker Value
Unknown

CVE-2019-0327

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.
0
Attacker Value
Unknown

CVE-2019-0321

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown

CVE-2019-0318

Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker to access information which would otherwise be restricted.
0