Show filters
181 Total Results
Displaying 141-150 of 181
Sort by:
Attacker Value
Unknown
CVE-2020-6202
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.
0
Attacker Value
Unknown
CVE-2015-7968
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
0
Attacker Value
Unknown
CVE-2020-6190
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.
0
Attacker Value
Unknown
CVE-2019-0389
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.
0
Attacker Value
Unknown
CVE-2019-0391
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2019-0355
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.
0
Attacker Value
Unknown
CVE-2019-0345
Disclosure Date: August 14, 2019 (last updated November 27, 2024)
A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request Forgery.
0
Attacker Value
Unknown
CVE-2019-0327
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.
0
Attacker Value
Unknown
CVE-2019-0321
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2019-0318
Disclosure Date: July 10, 2019 (last updated November 27, 2024)
Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker to access information which would otherwise be restricted.
0