Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 32264 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6310 1 Sap 2 Abap Platform, Netweaver Application Server Abap 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
CVE-2020-6302 1 Sap 1 Commerce 2024-11-21 7.5 HIGH 8.1 HIGH
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.
CVE-2020-6299 1 Sap 2 Abap Platform, Netweaver Application Server Abap 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
CVE-2020-6297 1 Sap 1 Data Intelligence 2024-11-21 2.1 LOW 4.4 MEDIUM
Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to access confidential system configuration information, that should otherwise be restricted, leading to Information Disclosure.
CVE-2020-6296 1 Sap 2 Abap Platform, Netweaver Application Server Abap 2024-11-21 6.5 MEDIUM 8.8 HIGH
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
CVE-2020-6285 1 Sap 1 Netweaver 2024-11-21 3.5 LOW 6.5 MEDIUM
SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
CVE-2020-6280 1 Sap 2 Abap Platform, Netweaver Application Server Abap 2024-11-21 4.0 MEDIUM 2.7 LOW
SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure.
CVE-2020-6269 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Under certain conditions SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
CVE-2020-6264 1 Sap 1 Commerce 2024-11-21 5.0 MEDIUM 7.5 HIGH
SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions which would otherwise be restricted, leading to Information Disclosure.
CVE-2020-6252 1 Sap 1 Adaptive Server Enterprise Cockpit 2024-11-21 5.2 MEDIUM 8.0 HIGH
Under certain conditions SAP Adaptive Server Enterprise (Cockpit), version 16.0, allows an attacker with access to local network, to get sensitive and confidential information, leading to Information Disclosure. It can be used to get user account credentials, tamper with system data and impact system availability.
CVE-2020-6251 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 5.0 MEDIUM 6.5 MEDIUM
Under certain conditions or error scenarios SAP Business Objects Business Intelligence Platform, version 4.2, allows an attacker to access information which would otherwise be restricted.
CVE-2020-6250 1 Sap 1 Adaptive Server Enterprise 2024-11-21 6.7 MEDIUM 6.8 MEDIUM
SAP Adaptive Server Enterprise, version 16.0, allows an authenticated attacker to exploit certain misconfigured endpoints exposed over the adjacent network, to read system administrator password leading to Information Disclosure. This could help the attacker to read/write any data and even stop the server like an administrator.
CVE-2020-6247 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 5.0 MEDIUM 7.5 HIGH
SAP Business Objects Business Intelligence Platform, version 4.2, allows an unauthenticated attacker to prevent legitimate users from accessing a service. Using a specially crafted request, the attacker can crash or flood the Central Management Server, thereby impacting system availability.
CVE-2020-6240 1 Sap 1 Netweaver Application Server Abap 2024-11-21 5.0 MEDIUM 7.5 HIGH
SAP NetWeaver AS ABAP (Web Dynpro ABAP), versions (SAP_UI 750, 752, 753, 754 and SAP_BASIS 700, 710, 730, 731, 804) allows an unauthenticated attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service leading to Denial of Service
CVE-2020-6237 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 5.0 MEDIUM 7.5 HIGH
Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web application allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.
CVE-2020-6234 1 Sap 1 Host Agent 2024-11-21 6.5 MEDIUM 7.2 HIGH
SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying operating system, leading to Privilege Escalation.
CVE-2020-6230 1 Sap 1 Orientdb 2024-11-21 6.5 MEDIUM 7.2 HIGH
SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application and lead to Code Injection. An attacker could thereby control the behavior of the application.
CVE-2020-6218 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 4.0 MEDIUM 5.0 MEDIUM
Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information that should otherwise be restricted, leading to Information Disclosure.
CVE-2020-6196 1 Sap 1 Businessobjects Mobile 2024-11-21 5.0 MEDIUM 7.5 HIGH
SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which he can block all the threads resulting in a Denial of Service.
CVE-2020-6164 1 Silverstripe 1 Silverstripe 2024-11-21 5.0 MEDIUM 7.5 HIGH
In SilverStripe through 4.5.0, a specific URL path configured by default through the silverstripe/framework module can be used to disclose the fact that a domain is hosting a Silverstripe application. There is no disclosure of the specific version. The functionality on this URL path is limited to execution in a CLI context, and is not known to present a vulnerability through web-based access. As a side-effect, this preconfigured path also blocks the creation of other resources on this path (e.g. a page).