|
196301
|
4.3 |
MEDIUM
Network
|
sap
|
abap_platform netweaver_application_server_abap
|
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP u…
|
NVD-CWE-noinfo
|
CVE-2020-6310
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196302
|
7.5 |
HIGH
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the atta…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-6309
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196303
|
8.1 |
HIGH
Network
|
sap
|
hcm_travel_management
|
SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of priv…
|
CWE-862
Missing Authorization
|
CVE-2020-6301
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196304
|
4.8 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6300
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196305
|
4.3 |
MEDIUM
Network
|
sap
|
abap_platform netweaver_application_server_abap
|
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Inform…
|
NVD-CWE-noinfo
|
CVE-2020-6299
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196306
|
8.1 |
HIGH
Network
|
sap
|
generic_market_data
|
SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Market Data (GMD) and change related GMD key figure val…
|
CWE-862
Missing Authorization
|
CVE-2020-6298
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196307
|
4.4 |
MEDIUM
Local
|
sap
|
data_intelligence
|
Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to access confidential system configuration information, that should otherwise be …
|
NVD-CWE-noinfo
|
CVE-2020-6297
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196308
|
8.8 |
HIGH
Network
|
sap
|
abap_platform netweaver_application_server_abap
|
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leadin…
|
NVD-CWE-noinfo
|
CVE-2020-6296
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196309
|
7.8 |
HIGH
Local
|
sap
|
adaptive_server_enterprise
|
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log fil…
|
CWE-532 CWE-732
Inclusion of Sensitive Information in Log Files Incorrect Permission Assignment for Critical Resource
|
CVE-2020-6295
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196310
|
9.1 |
CRITICAL
Network
|
sap
|
businessobjects_business_intelligence_platform
|
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-6294
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|