Show filters
53 Total Results
Displaying 51-53 of 53
Sort by:
Attacker Value
Unknown
CVE-2017-8913
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.
0
Attacker Value
Unknown
CVE-2016-10304
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788.
0
Attacker Value
Unknown
CVE-2016-9563
Disclosure Date: November 23, 2016 (last updated November 25, 2024)
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.
0