Show filters
52 Total Results
Displaying 41-50 of 52
Sort by:
Attacker Value
Unknown
CVE-2021-27603
Disclosure Date: April 13, 2021 (last updated November 28, 2024)
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to block all work processes thereby causing Denial of Service and affecting the Availability of the SAP system.
0
Attacker Value
Unknown
CVE-2021-21446
Disclosure Date: January 12, 2021 (last updated November 28, 2024)
SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, this has a high impact on the availability of the service.
0
Attacker Value
Unknown
CVE-2020-26835
Disclosure Date: December 09, 2020 (last updated February 22, 2025)
SAP NetWeaver AS ABAP, versions - 740, 750, 751, 752, 753, 754 , does not sufficiently encode URL which allows an attacker to input malicious java script in the URL which could be executed in the browser resulting in Reflected Cross-Site Scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2020-26818
Disclosure Date: November 10, 2020 (last updated February 22, 2025)
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
0
Attacker Value
Unknown
CVE-2020-26819
Disclosure Date: November 10, 2020 (last updated November 28, 2024)
SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.
0
Attacker Value
Unknown
CVE-2020-6371
Disclosure Date: October 15, 2020 (last updated November 28, 2024)
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731, 740, 750, leading to Information Disclosure.
0
Attacker Value
Unknown
CVE-2020-6299
Disclosure Date: August 12, 2020 (last updated November 28, 2024)
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
0
Attacker Value
Unknown
CVE-2020-6296
Disclosure Date: August 12, 2020 (last updated November 28, 2024)
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
0
Attacker Value
Unknown
CVE-2020-6310
Disclosure Date: August 12, 2020 (last updated November 28, 2024)
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
0
Attacker Value
Unknown
CVE-2020-6280
Disclosure Date: July 14, 2020 (last updated November 28, 2024)
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
0