Show filters
502 Total Results
Displaying 291-300 of 502
Sort by:
Attacker Value
Unknown
CVE-2020-6224
Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace files, when the user logs in and sends request with login credentials, leading to Information Disclosure.
0
Attacker Value
Unknown
CVE-2020-6229
Disclosure Date: April 14, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2020-6205
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
SAP NetWeaver AS ABAP Business Server Pages (Smart Forms), SAP_BASIS versions- 7.00, 7.01, 7.02, 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54; does not sufficiently encode user controlled inputs, allowing an unauthenticated attacker to non-permanently deface or modify displayed content and/or steal authentication information of the user and/or impersonate the user and access all information with the same rights as the target user, leading to Reflected Cross Site Scripting Vulnerability.
0
Attacker Value
Unknown
CVE-2020-6202
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.
0
Attacker Value
Unknown
CVE-2020-6203
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs, leading to Path Traversal.
0
Attacker Value
Unknown
CVE-2015-7968
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
0
Attacker Value
Unknown
CVE-2020-6187
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
SAP NetWeaver (Guided Procedures), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document input from a compromised admin, leading to Denial of Service.
0
Attacker Value
Unknown
CVE-2020-6184
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Under certain conditions, ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), does not sufficiently encode user-controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2020-6185
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Under certain conditions ABAP Online Community in SAP NetWeaver (SAP_BASIS version 7.40) and SAP S/4HANA (SAP_BASIS versions 7.50, 7.51, 7.52, 7.53, 7.54), allows an authenticated attacker to store a malicious payload which results in Stored Cross Site Scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-6181
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.
0