Filtered by vendor Sap
Subscriptions
Total
1493 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-21474 | 1 Sap | 1 Hana Database | 2024-08-03 | 6.5 Medium |
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter it in a way that the digest continues to be the same and without invalidating the digital signature, this allows them to impersonate as user in HANA database and be able to read the contents in the database. | ||||
CVE-2021-21464 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 4.3 Medium |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | ||||
CVE-2021-21480 | 1 Sap | 1 Manufacturing Integration And Intelligence | 2024-08-03 | 8.8 High |
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashboard is opened by users having at least SAP_XMII Developer role, malicious content in the dashboard gets executed, leading to remote code execution in the server, which allows privilege escalation. The malicious JSP code can contain certain OS commands, through which an attacker can read sensitive files in the server, modify files or even delete contents in the server thus compromising the confidentiality, integrity and availability of the server hosting the SAP MII application. Also, an attacker authenticated as a developer can use the application to upload and execute a file which will permit them to execute operating systems commands completely compromising the server hosting the application. | ||||
CVE-2021-21463 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 8.8 High |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | ||||
CVE-2021-21468 | 1 Sap | 1 Business Warehouse | 2024-08-03 | 6.5 Medium |
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table. | ||||
CVE-2021-21488 | 1 Sap | 1 Netweaver Knowledge Management | 2024-08-03 | 6.5 Medium |
Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability. | ||||
CVE-2021-21483 | 1 Sap | 1 Solution Manager | 2024-08-03 | 4.9 Medium |
Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensitive information which has a direct serious impact beyond the exploitable component thereby affecting the confidentiality in the application. | ||||
CVE-2021-21469 | 1 Sap | 1 Netweaver Master Data Management | 2024-08-03 | 7.5 High |
When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configuration. When no adequate protection has been enforced on any level (e.g., MDS Server password not set, network and OS configuration not properly secured, etc.), a malicious user might define UNC paths which could then be exploited to put the system at risk using a so-called SMB relay attack and obtain highly sensitive data, which leads to Information Disclosure. | ||||
CVE-2021-21460 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 8.8 High |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | ||||
CVE-2021-21453 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 8.8 High |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | ||||
CVE-2021-21452 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 8.8 High |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | ||||
CVE-2021-21484 | 1 Sap | 1 Hana | 2024-08-03 | 9.8 Critical |
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind. | ||||
CVE-2021-21458 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 8.8 High |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | ||||
CVE-2021-21481 | 1 Sap | 1 Netweaver | 2024-08-03 | 8.8 High |
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects, including such that grant administrative privileges. This could result in complete compromise of system confidentiality, integrity, and availability. | ||||
CVE-2021-21472 | 1 Sap | 1 Software Provisioning Manager | 2024-08-03 | 8.8 High |
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security attacks like Directory Traversal, Password Brute force Attack, SMB Relay attack, Security Downgrade. | ||||
CVE-2021-21489 | 1 Sap | 1 Netweaver Enterprise Portal | 2024-08-03 | 4.8 Medium |
SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with administrative privileges to store a malicious script on the portal. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of portal content. | ||||
CVE-2021-21485 | 1 Sap | 1 Netweaver Application Server Java | 2024-08-03 | 6.5 Medium |
An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Application Server for Java that allow the attacker to gain NTLM hashes of a privileged user. | ||||
CVE-2021-21450 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 8.8 High |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | ||||
CVE-2021-21467 | 1 Sap | 1 Banking Services | 2024-08-03 | 4.3 Medium |
SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business Partner Generic Market Data (GMD), due to improper authorization check. | ||||
CVE-2021-21455 | 1 Sap | 1 3d Visual Enterprise Viewer | 2024-08-03 | 8.8 High |
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. |