|
196901
|
4.8 |
MEDIUM
Network
|
sap
|
netweaver_design_time_repository
|
SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6370
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196902
|
5.9 |
MEDIUM
Network
|
sap
|
solution_manager focused_run
|
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords fo…
|
NVD-CWE-Other
|
CVE-2020-6369
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196903
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_composite_application_framework
|
There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspectin…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6367
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196904
|
6.5 |
MEDIUM
Network
|
sap
|
netweaver_compare_systems
|
SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files inclu…
|
CWE-20
Improper Input Validation
|
CVE-2020-6366
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196905
|
6.5 |
MEDIUM
Network
|
sap
|
banking_services
|
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulner…
|
CWE-863
Incorrect Authorization
|
CVE-2020-6362
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196906
|
5.5 |
MEDIUM
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive information when the victim loads the malicious f…
|
NVD-CWE-noinfo
|
CVE-2020-6315
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196907
|
7.5 |
HIGH
Network
|
rockwellautomation
|
flex_i\/o_1794-aent
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6085
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196908
|
7.5 |
HIGH
Network
|
rockwellautomation
|
flex_i\/o_1794-aent
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6084
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196909
|
5.3 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the i…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-6308
|
2024-11-21 14:35 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196910
|
7.8 |
HIGH
Local
|
f2fs-tools_project
|
f2fs-tools
|
An exploitable code execution vulnerability exists in the fsck_chk_orphan_node functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause a heap buffer overflow resulti…
|
CWE-787 CWE-131
Out-of-bounds Write Incorrect Calculation of Buffer Size
|
CVE-2020-6108
|
2024-11-21 14:35 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|