sap

1,568 tracked vulnerabilities.

CVE-2016-6148 HIGH
SAP HANA DB <1.00.73.00.389160 - DoS/RCE
Aug 05, 2016
CVSS 7.5
EPSS 0.03
CVE-2016-6147 CRITICAL
SAP TREX 7.10 Revision 63 - Remote Command Execution
Aug 05, 2016
CVSS 9.8
EPSS 0.11
CVE-2016-6145 MEDIUM
SAP HANA DB <1.00.091.00.1418659308 - SQL Injection
Aug 05, 2016
CVSS 5.3
EPSS 0.00
CVE-2016-6144 HIGH
SAP HANA <Revision 102 - SQL Injection
Aug 05, 2016
CVSS 8.1
EPSS 0.01
CVE-2016-6140 CRITICAL
SAP TREX 7.10 Revision 63 - Arbitrary File Write via RFC-Gateway
Aug 05, 2016
CVSS 9.8
EPSS 0.10
CVE-2016-6139 CRITICAL
SAP TREX 7.10- Revision 63 - Info Disclosure
Aug 05, 2016
CVSS 9.8
EPSS 0.05
CVE-2016-6138 CRITICAL
SAP TREX 7.10 Revision 63 - Path Traversal
Aug 05, 2016
CVSS 9.8
EPSS 0.16
CVE-2016-3640 MEDIUM
SAP HANA DB <1.00.091.00.1418659308 - Info Disclosure
Aug 05, 2016
CVSS 5.5
EPSS 0.00
CVE-2016-4018 HIGH
SAP HANA - Improper Access Control in Data Provisioning Agent
Apr 14, 2016
CVSS 7.3
EPSS 0.00
CVE-2016-4017 HIGH
SAP HANA - Denial of Service via Data Provisioning Agent
Apr 14, 2016
CVSS 7.5
EPSS 0.00
CVE-2016-4016 MEDIUM
SAP Manufacturing Integration and Intelligence 15 - Cross-Site Scripting via Title Parameter
Apr 14, 2016
CVSS 6.1
EPSS 0.00
CVE-2016-4015 HIGH
SAP NetWeaver JAVA AS 7.1-7.4 - Denial of Service via Crafted Request
Apr 14, 2016
CVSS 7.5
EPSS 0.03
CVE-2016-4014 HIGH
SAP NetWeaver JAVA AS 7.4 - XML External Entity Injection in UDDI Component
Apr 14, 2016
CVSS 8.6
EPSS 0.07
CVE-2016-3980 HIGH
SAP Application Server Java 7.2-7.4 - Denial of Service via Crafted HTTP Request
Apr 08, 2016
CVSS 7.5
EPSS 0.03
CVE-2016-3979 HIGH
SAP Java AS 7.2-7.4 - Denial of Service via IctParseCookies HTTP Request
Apr 08, 2016
CVSS 7.5
EPSS 0.04
CVE-2016-3976 HIGH KEV
SAP NetWeaver AS Java <7.6 - Path Traversal
Apr 07, 2016
CVSS 7.5
EPSS 0.76
CVE-2016-3975 MEDIUM
SAP NetWeaver AS Java 7.1-7.5 - Cross-Site Scripting via NavigationURLTester
Apr 07, 2016
CVSS 6.1
EPSS 0.01
CVE-2016-3974 CRITICAL
SAP NetWeaver Application Server Java 7.10-7.50 - XML External Entity Injection via ServerNodesWSService
Apr 07, 2016
CVSS 9.1
EPSS 0.14
CVE-2016-3973 MEDIUM
SAP NetWeaver Java AS <7.5 - Info Disclosure
Apr 07, 2016
CVSS 5.3
EPSS 0.01
CVE-2016-2536 HIGH
SAP 3D Visual Enterprise Viewer - Remote Code Execution via Crafted SketchUp Document
Feb 22, 2016
CVSS 8.8
EPSS 0.01
CVE-2016-2389 HIGH NUCLEI
SAP NetWeaver xMII 15.0 - Directory Traversal via GetFileList Path Parameter
Feb 16, 2016
CVSS 7.5
EPSS 0.84
CVE-2016-2388 MEDIUM KEV
SAP NetWeaver AS JAVA 7.10-7.50 - Exposure of Sensitive Information via Universal Worklist Configuration
Feb 16, 2016
CVSS 5.3
EPSS 0.68
CVE-2016-2387 MEDIUM
SAP NetWeaver 7.4 - Cross-Site Scripting via ProxyServer Servlet Parameters
Feb 16, 2016
CVSS 6.1
EPSS 0.00
CVE-2016-2386 CRITICAL KEV
SAP NetWeaver Application Server Java 7.40 - SQL Injection
Feb 16, 2016
CVSS 9.8
EPSS 0.44
CVE-2016-1929 CRITICAL
SAP HANA - Denial of Service via Log Spoofing in XS Engine
Jan 20, 2016
CVSS 9.3
EPSS 0.01