Vulnerabilities
Vulnerable Software
Sap:  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver Business Client (NWBC) for HTML 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) roundtrips parameter, aka SAP Security Note 2051285.
CVSS Score
4.3
EPSS Score
0.018
Published
2015-01-07
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905.
CVSS Score
10.0
EPSS Score
0.046
Published
2014-12-17
Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alias.
CVSS Score
7.5
EPSS Score
0.039
Published
2014-12-11
Multiple unspecified vulnerabilities in SAP Governance, Risk, and Compliance (GRC) allow remote authenticated users to gain privileges and execute arbitrary programs via a crafted (1) RFC or (2) SOAP-RFC request.
CVSS Score
9.0
EPSS Score
0.036
Published
2014-11-19
Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files via unspecified vectors.
CVSS Score
5.0
EPSS Score
0.019
Published
2014-11-06
SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.
CVSS Score
7.2
EPSS Score
0.004
Published
2014-11-06
The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.
CVSS Score
10.0
EPSS Score
0.028
Published
2014-11-06
Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors related to session handling.
CVSS Score
7.8
EPSS Score
0.013
Published
2014-11-06
SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.012
Published
2014-11-06
SQL injection vulnerability in Product Safety (EHS-SAF) component in SAP Environment, Health, and Safety Management allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
7.5
EPSS Score
0.013
Published
2014-11-06


Contact Us

Shodan ® - All rights reserved