Show filters
1,202 Total Results
Displaying 181-190 of 1,202
Sort by:
Attacker Value
Unknown

CVE-2021-36205

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
Under certain circumstances the session token is not cleared on logout.
Attacker Value
Unknown

CVE-2022-27669

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
Attacker Value
Unknown

CVE-2021-36202

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.
Attacker Value
Unknown

CVE-2022-26103

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
Attacker Value
Unknown

CVE-2022-26102

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available with in the same SAP system even if he/she isn't authorized for that transaction. A successful exploitation could expose information and in worst case manipulate data before the start screen is executed, resulting in limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2021-39038

Disclosure Date: February 23, 2022 (last updated February 23, 2025)
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 213968.
Attacker Value
Unknown

CVE-2022-22540

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Successful attacks could result in disclosure of a table of contents from the system, but no risk of modification possible.
Attacker Value
Unknown

CVE-2022-22532

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This could allow the malicious payload to be executed and hence execute functions that could be impersonating the victim or even steal the victim's logon session.
Attacker Value
Unknown

CVE-2022-22536

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.
Attacker Value
Unknown

CVE-2022-22533

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP server requests resulting in errors, such that it consumes the memory buffer. This could result in system shutdown rendering the system unavailable.