Show filters
1,715 Total Results
Displaying 61-70 of 1,715
Sort by:
Attacker Value
Unknown

CVE-2024-47590

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability.
0
Attacker Value
Unknown

CVE-2024-47588

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to a high impact on confidentiality, with no impact on integrity or availability.
0
Attacker Value
Unknown

CVE-2024-47587

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.
0
Attacker Value
Unknown

CVE-2024-47586

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.
0
Attacker Value
Unknown

CVE-2024-42372

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown

CVE-2024-47594

Disclosure Date: October 08, 2024 (last updated November 15, 2024)
SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick the user into clicking it. When a victim who is registered on the portal clicks on such link, confidentiality and integrity of their web browser session could be compromised.
Attacker Value
Unknown

CVE-2024-45282

Disclosure Date: October 08, 2024 (last updated November 15, 2024)
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.
Attacker Value
Unknown

CVE-2024-45278

Disclosure Date: October 08, 2024 (last updated November 15, 2024)
SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2024-45277

Disclosure Date: October 08, 2024 (last updated November 15, 2024)
The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.
Attacker Value
Unknown

CVE-2024-37179

Disclosure Date: October 08, 2024 (last updated November 15, 2024)
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.