Skip to main content

Vendor/product archive

sap / content_server CVEs

Beta · best-effort

6 CVEs tagged to sap / content_server2 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-40309

Published Sep 12, 2023

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2023-40308

Published Sep 12, 2023

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-26457

Published Mar 14, 2023

SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an at…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4157

Published Jun 2, 2015

SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1