Show filters
502 Total Results
Displaying 301-310 of 502
Sort by:
Attacker Value
Unknown
CVE-2020-6193
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
SAP NetWeaver (Knowledge Management ICE Service), versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to execute malicious scripts leading to Reflected Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2020-6190
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Certain vulnerable endpoints in SAP NetWeaver AS Java (Heap Dump Application), versions 7.30, 7.31, 7.40, 7.50, provide valuable information about the system like hostname, server node and installation path that could be misused by an attacker leading to Information Disclosure.
0
Attacker Value
Unknown
CVE-2011-1517
Disclosure Date: February 05, 2020 (last updated November 28, 2024)
SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.
0
Attacker Value
Unknown
CVE-2013-1593
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04 when sending a crafted SAP Message Server packet to TCP ports 36NN and/or 39NN.
0
Attacker Value
Unknown
CVE-2013-1592
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code.
0
Attacker Value
Unknown
CVE-2020-6304
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
Improper input validation in SAP NetWeaver Internet Communication Manager (update provided in KRNL32NUC & KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT KRNL64NUC & KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49 KERNEL 7.21, 7.49, 7.53) allows an attacker to prevent users from accessing its services through a denial of service.
0
Attacker Value
Unknown
CVE-2019-0389
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.
0
Attacker Value
Unknown
CVE-2019-0391
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2012-5193
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php, (4) days parameter to stats/index.php, (5) login parameter to users/register.php, or (6) highlight parameter.
0
Attacker Value
Unknown
CVE-2019-0367
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization checks for an authenticated user, allowing the import of B2B table content that leads to Missing Authorization Check.
0