Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-27902

Disclosure Date: March 12, 2024 (last updated April 01, 2024)
Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. A successful attack can allow a malicious attacker to access and modify data through their ability to execute code in a user’s browser. There is no impact on the availability of the system
0
Attacker Value
Unknown

CVE-2007-4475

Disclosure Date: April 01, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a long argument to the SaveViewToSessionFile method.
0
Attacker Value
Unknown

CVE-2008-4387

Disclosure Date: November 10, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet Explorer.
0
Attacker Value
Unknown

CVE-2008-0621

Disclosure Date: February 06, 2008 (last updated October 04, 2023)
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands.
0
Attacker Value
Unknown

CVE-2008-0620

Disclosure Date: February 06, 2008 (last updated October 04, 2023)
SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LPD command, which causes the server to terminate.
0
Attacker Value
Unknown

CVE-2002-1579

Disclosure Date: April 15, 2004 (last updated February 22, 2025)
SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.
0
Attacker Value
Unknown

CVE-2003-1035

Disclosure Date: April 15, 2004 (last updated February 22, 2025)
The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.
0