Skip to main content

Vendor/product archive

sap / sap_web_application_server CVEs

Beta · best-effort

12 CVEs tagged to sap / sap_web_application_server0 Critical, 1 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2006-6010

Published Nov 21, 2006

SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnera…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6011

Published Nov 21, 2006

Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers to cause a denial of service (enserver.exe crash) via a certain UDP packet to p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5784

Published Nov 7, 2006

Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5785

Published Nov 7, 2006

Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to cause a denial of service (enserver.exe crash) vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1039

Published Mar 7, 2006

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or h…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3633

Published Nov 16, 2005

HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitrary HTML headers via the sap-ex…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3634

Published Nov 16, 2005

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3635

Published Nov 16, 2005

Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3636

Published Nov 16, 2005

Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1