Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Total 1541 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4407 1 Sap 1 Sapcryptolib 2025-04-12 4.0 MEDIUM 6.5 MEDIUM
The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors, aka SAP Security Note 2223008.
CVE-2015-7986 1 Sap 1 Hana 2025-04-12 7.5 HIGH N/A
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka SAP Security Note 2197428.
CVE-2015-4157 1 Sap 1 Content Server 2025-04-12 5.0 MEDIUM N/A
SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.
CVE-2015-8330 1 Sap 1 Plant Connectivity 2025-04-12 7.8 HIGH N/A
The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption and agent crash) via crafted xMII requests, aka SAP Security Note 2238619.
CVE-2015-2815 1 Sap 1 Netweaver 2025-04-12 6.5 MEDIUM N/A
Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2063369.
CVE-2016-5845 1 Sap 1 Sapcar 2025-04-12 2.1 LOW 5.5 MEDIUM
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of service (program crash) via an invalid file name in an archive file, aka SAP Security Note 2312905.
CVE-2015-7239 1 Sap 1 Netweaver J2ee Engine 2025-04-12 7.5 HIGH N/A
SQL injection vulnerability in the BP_FIND_JOBS_WITH_PROGRAM function module in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-5847 1 Sap 1 Sapcar Archive Tool 2025-04-12 4.4 MEDIUM 5.8 MEDIUM
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
CVE-2014-4012 1 Sap 1 Open Hub Service 2025-04-12 5.0 MEDIUM N/A
SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
CVE-2015-2817 1 Sap 1 Netweaver 2025-04-12 5.0 MEDIUM N/A
The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.
CVE-2014-5172 1 Sap 1 Hana 2025-04-12 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-8659 1 Sap 1 Environment Health And Safety 2025-04-12 5.0 MEDIUM N/A
Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2015-3621 1 Sap 1 Enterprise Central Component 2025-04-12 9.3 HIGH N/A
Untrusted search path vulnerability in SAP Enterprise Central Component (ECC) allows local users to gain privileges via a Trojan horse program.
CVE-2016-6137 1 Sap 1 Trex 2025-04-12 10.0 HIGH 9.8 CRITICAL
An unspecified function in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands via unknown vectors, aka SAP Security Note 2203591.
CVE-2015-3979 1 Sap 1 Customer Relationship Management 2025-04-12 7.5 HIGH N/A
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
CVE-2014-2749 1 Sap 1 Hana 2025-04-12 5.0 MEDIUM N/A
The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive information via a malformed HTTP GET request.
CVE-2013-7360 1 Sap 1 Adminadapter 2025-04-12 7.5 HIGH N/A
Unspecified vulnerability in SAP adminadapter allows remote attackers to read or write to arbitrary files via unknown vectors.
CVE-2013-7367 1 Sap 1 Enterprise Portal 2025-04-12 7.5 HIGH N/A
SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via unspecified vectors.
CVE-2015-6662 1 Sap 1 Netweaver 2025-04-12 6.8 MEDIUM N/A
XML external entity (XXE) vulnerability in SAP NetWeaver Portal 7.4 allows remote attackers to read arbitrary files and possibly have other unspecified impact via crafted XML data, aka SAP Security Note 2168485.
CVE-2014-2752 1 Sap 1 Business Object Processing Framework For Abap 2025-04-12 7.5 HIGH N/A
SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.