|
196861
|
6.1 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP resp…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6201
|
2024-11-21 14:35 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196862
|
5.4 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6200
|
2024-11-21 14:35 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196863
|
5.4 |
MEDIUM
Network
|
sap
|
erp
|
The view FIMENAV_COMPCERT in SAP ERP (MENA Certificate Management), EAPPGLO version 607, SAP_FIN versions- 618, 730 and SAP S/4HANA (MENA Certificate Management), S4CORE versions- 100, 101, 102, 103,…
|
CWE-862
Missing Authorization
|
CVE-2020-6199
|
2024-11-21 14:35 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196864
|
9.8 |
CRITICAL
Network
|
sap
|
solution_manager
|
SAP Solution Manager (Diagnostics Agent), version 720, allows unencrypted connections from unauthenticated sources. This allows an attacker to control all remote functions on the Agent due to Missing…
|
CWE-306 CWE-319
Missing Authentication for Critical Function Cleartext Transmission of Sensitive Information
|
CVE-2020-6198
|
2024-11-21 14:35 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196865
|
3.3 |
LOW
Local
|
sap
|
enable_now
|
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download …
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-6197
|
2024-11-21 14:35 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196866
|
7.5 |
HIGH
Network
|
sap
|
businessobjects_mobile
|
SAP BusinessObjects Mobile (MobileBIService), version 4.2, allows an attacker to generate multiple requests, using which he can block all the threads resulting in a Denial of Service.
|
NVD-CWE-noinfo
|
CVE-2020-6196
|
2024-11-21 14:35 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196867
|
5.4 |
MEDIUM
Network
|
sap
|
enable_now
|
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
|
CWE-200
Information Exposure
|
CVE-2020-6178
|
2024-11-21 14:35 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196868
|
8.8 |
HIGH
Network
|
google fedoraproject redhat debian
|
chrome fedora enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-843
Type Confusion
|
CVE-2020-6418
|
2024-11-21 14:35 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196869
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-6407
|
2024-11-21 14:35 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196870
|
8.8 |
HIGH
Network
|
google fedoraproject redhat debian
|
chrome fedora enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-416
Use After Free
|
CVE-2020-6386
|
2024-11-21 14:35 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|