|
196481
|
5.5 |
MEDIUM
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted sources which results in crashing of the applicati…
|
CWE-20
Improper Input Validation
|
CVE-2020-6375
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196482
|
7.8 |
HIGH
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which results in crashing of the application and becomin…
|
CWE-20 CWE-125
Improper Input Validation Out-of-bounds Read
|
CVE-2020-6374
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196483
|
7.8 |
HIGH
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-6373
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196484
|
7.8 |
HIGH
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-6372
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196485
|
4.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server_abap
|
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions -…
|
NVD-CWE-noinfo
|
CVE-2020-6371
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196486
|
5.4 |
MEDIUM
Network
|
sap
|
business_planning_and_consolidation
|
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorizat…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6368
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196487
|
10.0 |
CRITICAL
Network
|
sap
|
introscope_enterprise_manager
|
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentia…
|
CWE-78
OS Command
|
CVE-2020-6364
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196488
|
4.6 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with userna…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-6363
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196489
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_enterprise_portal
|
SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6323
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196490
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different sy…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6319
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|