|
197651
|
6.2 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace file…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-6224
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197652
|
6.1 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user w…
|
CWE-601
Open Redirect
|
CVE-2020-6223
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197653
|
5.4 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) …
|
CWE-79
Cross-site Scripting
|
CVE-2020-6222
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197654
|
5.4 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS)…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6221
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197655
|
8.8 |
HIGH
Network
|
sap
|
businessobjects_business_intelligence_platform crystal_reports_for_visual_studio
|
SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-6219
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197656
|
5.0 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to access information that should otherwise be restricted, leading to Infor…
|
NVD-CWE-noinfo
|
CVE-2020-6218
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197657
|
6.1 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-6216
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197658
|
4.7 |
MEDIUM
Network
|
sap
|
s\/4hana
|
SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorization objects, exploita…
|
CWE-863
Incorrect Authorization
|
CVE-2020-6214
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197659
|
6.5 |
MEDIUM
Network
|
google debian fedoraproject opensuse
|
chrome debian_linux fedora leap backports
|
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-6456
|
2024-11-21 14:35 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197660
|
8.8 |
HIGH
Network
|
google debian fedoraproject opensuse
|
chrome debian_linux fedora leap backports
|
Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6455
|
2024-11-21 14:35 |
2020-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|