Show filters
1,199 Total Results
Displaying 41-50 of 1,199
Sort by:
Attacker Value
Unknown

CVE-2024-47593

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.
0
Attacker Value
Unknown

CVE-2024-47592

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
0
Attacker Value
Unknown

CVE-2024-47586

Disclosure Date: November 12, 2024 (last updated February 27, 2025)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.
0
Attacker Value
Unknown

CVE-2024-45087

Disclosure Date: November 11, 2024 (last updated February 27, 2025)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-45086

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Attacker Value
Unknown

CVE-2024-45072

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.
Attacker Value
Unknown

CVE-2024-45071

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-45085

Disclosure Date: October 15, 2024 (last updated February 26, 2025)
IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an unexpected specially crafted request. A remote attacker could exploit this vulnerability to cause an error resulting in a denial of service.
Attacker Value
Unknown

CVE-2024-45073

Disclosure Date: September 30, 2024 (last updated February 26, 2025)
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Attacker Value
Unknown

CVE-2024-45285

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By sending a crafted packet in the function module targeting specific parameters, the specific targeted user will no longer have access to any functionality of SAP GUI. There is low impact on integrity and availability of the application.
0