|
197641
|
8.6 |
HIGH
Network
|
sap
|
solution_manager
|
SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities of the Collector Simulator, leading to Missing Authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-6235
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197642
|
7.2 |
HIGH
Network
|
sap
|
host_agent
|
SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying operating system, leading to Privilege Escalation.
|
NVD-CWE-noinfo
|
CVE-2020-6234
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197643
|
4.3 |
MEDIUM
Network
|
sap
|
s\/4hana_financial_products_subledger banking_services_from_sap
|
SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization C…
|
CWE-862
Missing Authorization
|
CVE-2020-6233
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197644
|
5.3 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.
|
CWE-862
Missing Authorization
|
CVE-2020-6232
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197645
|
5.4 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulner…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6231
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197646
|
7.2 |
HIGH
Network
|
sap
|
orientdb
|
SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application and lead to Code Injection. An attacker could …
|
NVD-CWE-noinfo
|
CVE-2020-6230
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197647
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_as_abap_business_server_pages
|
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user con…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6229
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197648
|
7.5 |
HIGH
Network
|
sap
|
business_client
|
SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer.
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-6228
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197649
|
7.5 |
HIGH
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, …
|
CWE-20 CWE-116
Improper Input Validation Improper Encoding or Escaping of Output
|
CVE-2020-6227
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197650
|
5.4 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulner…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6226
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|