Skip to main content

Vendor archive

sap CVEs

Beta · best-effort

1,580 CVEs tagged to vendor sap157 Critical, 458 High, 911 Medium, 54 Low, 0 Unrated.

CVE-2005-4815

Published Dec 31, 2005

SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3633

Published Nov 16, 2005

HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitrary HTML headers via the sap-ex…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3634

Published Nov 16, 2005

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3635

Published Nov 16, 2005

Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3636

Published Nov 16, 2005

Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1691

Published Jul 26, 2005

Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." sequences in an HTTP GET request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1576

Published Apr 15, 2004

lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserv…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1577

Published Apr 15, 2004

SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLY…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1578

Published Apr 15, 2004

The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1579

Published Apr 15, 2004

SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1033

Published Apr 15, 2004

The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1034

Published Apr 15, 2004

The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those p…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1035

Published Apr 15, 2004

The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1036

Published Apr 15, 2004

Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1037

Published Apr 15, 2004

Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1038

Published Apr 15, 2004

The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, whi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1039

Published Apr 15, 2004

Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0938

Published Dec 15, 2003

vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0939

Published Dec 15, 2003

eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0940

Published Dec 15, 2003

Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0941

Published Dec 15, 2003

web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0942

Published Dec 15, 2003

Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0943

Published Dec 15, 2003

web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redir…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0944

Published Dec 15, 2003

Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL with a long requestURI.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0945

Published Dec 15, 2003

The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,551-1,575 of 1,580 CVEsPage 63 of 64