|
197111
|
4.3 |
MEDIUM
Network
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-6328
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197112
|
4.3 |
MEDIUM
Network
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-6327
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197113
|
5.4 |
MEDIUM
Network
|
sap
|
netweaver_knowledge_management
|
SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6326
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197114
|
4.3 |
MEDIUM
Network
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6322
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197115
|
6.5 |
MEDIUM
Network
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated U3D file received from untrusted sources which results in crashing of the application and becoming temporarily unavaila…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2020-6321
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197116
|
8.1 |
HIGH
Network
|
sap
|
marketing
|
SAP Marketing (Servlet), version-130,140,150, allows an authenticated attacker to invoke certain functions that are restricted. Limited knowledge of payload is required for an attacker to exploit the…
|
NVD-CWE-noinfo
|
CVE-2020-6320
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197117
|
4.3 |
MEDIUM
Network
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavail…
|
CWE-20
Improper Input Validation
|
CVE-2020-6314
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197118
|
6.5 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver Application Server JAVA(XML Forms) versions 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user controlled inputs, which allows an authenticated User with special roles to store ma…
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2020-6313
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197119
|
8.1 |
HIGH
Network
|
sap
|
commerce
|
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or …
|
NVD-CWE-noinfo
|
CVE-2020-6302
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197120
|
7.2 |
HIGH
Network
|
sap
|
abap_platform
|
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code…
|
CWE-94
Code Injection
|
CVE-2020-6318
|
2024-11-21 14:35 |
2020-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|