Skip to main content

Vendor archive

sap CVEs

Beta · best-effort

1,580 CVEs tagged to vendor sap157 Critical, 458 High, 911 Medium, 54 Low, 0 Unrated.

CVE-2007-3608

Published Jul 6, 2007

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3613

Published Jul 6, 2007

Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3614

Published Jul 6, 2007

Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a cer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1914

Published Apr 10, 2007

The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6345

Published Dec 7, 2006

Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6346

Published Dec 7, 2006

Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote attackers to cause a denial of se…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6010

Published Nov 21, 2006

SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnera…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6011

Published Nov 21, 2006

Unspecified vulnerability in SAP Web Application Server before 6.40 patch 6 allows remote attackers to cause a denial of service (enserver.exe crash) via a certain UDP packet to p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5784

Published Nov 7, 2006

Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5785

Published Nov 7, 2006

Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to cause a denial of service (enserver.exe crash) vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5114

Published Oct 3, 2006

Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4133

Published Aug 14, 2006

Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial of service (crash) or execute a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4134

Published Aug 14, 2006

Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attackers to cause a denial of serv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2547

Published May 23, 2006

Unspecified vulnerability in the sapdba command in SAP with Informix before 700, and 700 up to patch 100, allows local users to execute arbitrary commands via unknown vectors rela…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-1039

Published Mar 7, 2006

SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or h…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0731

Published Feb 16, 2006

WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter,…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0732

Published Feb 16, 2006

Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,526-1,550 of 1,580 CVEsPage 62 of 64