|
197061
|
8.8 |
HIGH
Network
|
sap
|
abap_platform netweaver_application_server_abap
|
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leadin…
|
NVD-CWE-noinfo
|
CVE-2020-6296
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197062
|
7.8 |
HIGH
Local
|
sap
|
adaptive_server_enterprise
|
Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log fil…
|
CWE-532 CWE-732
Inclusion of Sensitive Information in Log Files Incorrect Permission Assignment for Critical Resource
|
CVE-2020-6295
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197063
|
9.1 |
CRITICAL
Network
|
sap
|
businessobjects_business_intelligence_platform
|
Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-6294
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197064
|
6.5 |
MEDIUM
Network
|
sap
|
netweaver_knowledge_management
|
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files bu…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-6293
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197065
|
9.0 |
CRITICAL
Network
|
sap
|
netweaver_knowledge_management
|
SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6284
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197066
|
4.3 |
MEDIUM
Network
|
sap
|
s\/4_hana_fiori_ui_for_general_ledger_accounting
|
SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attac…
|
CWE-862
Missing Authorization
|
CVE-2020-6273
|
2024-11-21 14:35 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197067
|
8.8 |
HIGH
Network
|
frappe
|
erpnext
|
An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenti…
|
CWE-89
SQL Injection
|
CVE-2020-6145
|
2024-11-21 14:35 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197068
|
7.8 |
HIGH
Local
|
f2fs-tools_project fedoraproject
|
f2fs-tools fedora
|
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operation…
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2020-6070
|
2024-11-21 14:35 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197069
|
7.5 |
HIGH
Network
|
freediameter
|
freediameter
|
An exploitable denial of service vulnerability exists in the freeDiameter functionality of freeDiameter 1.3.2. A specially crafted Diameter request can trigger a memory corruption resulting in denial…
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2020-6098
|
2024-11-21 14:35 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197070
|
4.3 |
MEDIUM
Network
|
google debian opensuse fedoraproject
|
chrome debian_linux leap fedora backports_sle
|
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted…
|
NVD-CWE-Other
|
CVE-2020-6536
|
2024-11-21 14:35 |
2020-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|