|
194901
|
6.5 |
MEDIUM
Network
|
sap
|
focused_run
|
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP E…
|
CWE-862
Missing Authorization
|
CVE-2021-27609
|
2024-11-21 14:58 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194902
|
4.3 |
MEDIUM
Network
|
sap
|
fiori_apps_2.0_for_travel_management_in_sap_erp
|
SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resu…
|
CWE-862
Missing Authorization
|
CVE-2021-27605
|
2024-11-21 14:58 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194903
|
6.5 |
MEDIUM
Network
|
sap
|
netweaver_application_server_abap
|
An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function modu…
|
NVD-CWE-noinfo
|
CVE-2021-27603
|
2024-11-21 14:58 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194904
|
9.9 |
CRITICAL
Network
|
sap
|
commerce
|
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modu…
|
CWE-94
Code Injection
|
CVE-2021-27602
|
2024-11-21 14:58 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194905
|
5.4 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a C…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27601
|
2024-11-21 14:58 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194906
|
5.4 |
MEDIUM
Network
|
sap
|
manufacturing_execution
|
SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parameter and send it to the server because SAP Manufact…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27600
|
2024-11-21 14:58 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194907
|
5.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of mis…
|
CWE-862
Missing Authorization
|
CVE-2021-27598
|
2024-11-21 14:58 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194908
|
9.8 |
CRITICAL
Network
|
apache
|
solr
|
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandl…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-27905
|
2024-11-21 14:58 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194909
|
7.8 |
HIGH
Local
|
fatek
|
winproladder
|
FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-bounds write and allow an attacker to execute arbitrary code.
|
-
|
CVE-2021-27486
|
2024-11-21 14:58 |
2021-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194910
|
6.1 |
MEDIUM
Network
|
squirro
|
squirro
|
The Squirro Insights Engine was affected by a Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.0.0 up to and including 3.2.4. An attacker can use the vulnerability to inject ma…
|
CWE-79
Cross-site Scripting
|
CVE-2021-27945
|
2024-11-21 14:58 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|