Vulnerabilities (CVE)

Filtered by CWE-79
Total 37850 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6312 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to stored Cross Site Scripting. In certain situations, when a user accesses an affected web page element, the attacker will be able to access or modify metadata for which they are not authorized.
CVE-2020-6305 1 Sap 1 Process Integration 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
PI Rest Adapter of SAP Process Integration (update provided in SAP_XIAF 7.31, 7.40, 7.50) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6303 1 Sap 1 Disclosure Management 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Disclosure Management, before version 10.1, does not validate user input properly in specific use cases leading to Cross-Site Scripting.
CVE-2020-6300 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 4.8 MEDIUM
SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not sufficiently encode user-controlled inputs for RecycleBin, resulting in Stored Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6284 1 Sap 1 Netweaver Knowledge Management 2024-11-21 8.5 HIGH 9.0 CRITICAL
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of the script content could result in complete compromise of system confidentiality, integrity and availability, leading to Stored Cross Site Scripting.
CVE-2020-6283 1 Sap 1 Fiori Launchpad 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.
CVE-2020-6281 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting.
CVE-2020-6278 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the victim opens these files, leading to Stored Cross Site Scripting
CVE-2020-6276 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.
CVE-2020-6272 1 Sap 1 Commerce Cloud 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page is visited, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6257 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad) 4.2 does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability.
CVE-2020-6254 1 Sap 1 Enterprise Threat Detection 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.
CVE-2020-6246 1 Sap 1 Netweaver As Abap Business Server Pages 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver AS ABAP Business Server Pages Test Application SBSPEXT_TABLE, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6231 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6229 1 Sap 1 Netweaver As Abap Business Server Pages 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6226 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6222 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6221 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2020-6220 1 Sap 1 Business Objects Business Intelligence Platform 2024-11-21 2.6 LOW 4.7 MEDIUM
BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.
CVE-2020-6217 1 Sap 1 Netweaver As Abap Business Server Pages 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.