|
196921
|
4.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server_abap
|
User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions -…
|
NVD-CWE-noinfo
|
CVE-2020-6371
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196922
|
5.4 |
MEDIUM
Network
|
sap
|
business_planning_and_consolidation
|
SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorizat…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6368
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196923
|
10.0 |
CRITICAL
Network
|
sap
|
introscope_enterprise_manager
|
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an attacker to modify a cookie in a way that OS commands can be executed and potentia…
|
CWE-78
OS Command
|
CVE-2020-6364
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196924
|
4.6 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with userna…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-6363
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196925
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_enterprise_portal
|
SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6323
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196926
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver Application Server Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 allows an unauthenticated attacker to include JavaScript blocks in any web page or URL with different sy…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6319
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196927
|
5.4 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several we…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6272
|
2024-11-21 14:35 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196928
|
7.5 |
HIGH
Network
|
rockwellautomation
|
allen-bradley_flex_io_1794-aent\/b_firmware
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6083
|
2024-11-21 14:35 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196929
|
7.5 |
HIGH
Network
|
rockwellautomation
|
flex_i\/o_1794-aent\/b_firmware
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6087
|
2024-11-21 14:35 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196930
|
7.5 |
HIGH
Network
|
rockwellautomation
|
flex_i\/o_1794-aent\/b_firmware
|
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-6086
|
2024-11-21 14:35 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|