Vulnerabilities
Vulnerable Software
Sap:  Security Vulnerabilities
Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be restricted.
CVSS Score
5.3
EPSS Score
0.013
Published
2018-05-09
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
CVSS Score
5.5
EPSS Score
0.018
Published
2018-05-09
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
CVSS Score
3.7
EPSS Score
0.009
Published
2018-05-09
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
CVSS Score
6.5
EPSS Score
0.016
Published
2018-05-09
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
CVSS Score
5.3
EPSS Score
0.025
Published
2018-05-09
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.
CVSS Score
5.4
EPSS Score
0.012
Published
2018-04-10
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
CVSS Score
4.3
EPSS Score
0.02
Published
2018-04-10
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
CVSS Score
5.4
EPSS Score
0.01
Published
2018-04-10
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.
CVSS Score
5.3
EPSS Score
0.004
Published
2018-04-10
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.
CVSS Score
7.3
EPSS Score
0.016
Published
2018-04-10


Contact Us

Shodan ® - All rights reserved