|
208631
|
7.8 |
HIGH
Local
|
sap
|
3d_visual_enterprise_viewer
|
SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavai…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-26817
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208632
|
4.9 |
MEDIUM
Network
|
sap
|
process_integration_\(pgp_module_-_business-to-business_add_on\)
|
SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these…
|
NVD-CWE-noinfo
|
CVE-2020-26814
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208633
|
5.3 |
MEDIUM
Network
|
sap
|
commerce_cloud_\(accelerator_payment_mock\)
|
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26811
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208634
|
7.5 |
HIGH
Network
|
sap
|
commerce_cloud_\(accelerator_payment_mock\)
|
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL…
|
NVD-CWE-noinfo
|
CVE-2020-26810
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208635
|
8.6 |
HIGH
Network
|
sap
|
fiori_launchpad_\(news_tile_application\)
|
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to targe…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-26815
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208636
|
5.3 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26809
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208637
|
7.2 |
HIGH
Network
|
sap
|
sap_s4_hana\(dmis\) sap_as_abap\(dmis\)
|
SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticat…
|
NVD-CWE-noinfo
|
CVE-2020-26808
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208638
|
3.3 |
LOW
Local
|
sap
|
erp_client_for_e-bilanz
|
SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-26807
|
2024-11-21 14:20 |
2020-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208639
|
5.5 |
MEDIUM
Local
|
trendmicro
|
interscan_messaging_security_virtual_appliance
|
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an information disclosure vulnerability which could allow an attacker to access a specific database and key.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-27019
|
2024-11-21 14:20 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208640
|
5.5 |
MEDIUM
Local
|
trendmicro
|
interscan_messaging_security_virtual_appliance
|
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to a server side request forgery vulnerability which could allow an authenticated attacker to abuse the product's …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-27018
|
2024-11-21 14:20 |
2020-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|