|
196471
|
7.2 |
HIGH
Network
|
sap
|
host_agent
|
SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying operating system, leading to Privilege Escalation.
|
NVD-CWE-noinfo
|
CVE-2020-6234
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196472
|
4.3 |
MEDIUM
Network
|
sap
|
s\/4hana_financial_products_subledger banking_services_from_sap
|
SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization C…
|
CWE-862
Missing Authorization
|
CVE-2020-6233
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196473
|
5.3 |
MEDIUM
Network
|
sap
|
commerce_cloud
|
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.
|
CWE-862
Missing Authorization
|
CVE-2020-6232
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196474
|
5.4 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulner…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6231
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196475
|
7.2 |
HIGH
Network
|
sap
|
orientdb
|
SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application and lead to Code Injection. An attacker could …
|
NVD-CWE-noinfo
|
CVE-2020-6230
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196476
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_as_abap_business_server_pages
|
SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not sufficiently encode user con…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6229
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196477
|
7.5 |
HIGH
Network
|
sap
|
business_client
|
SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attacker under certain conditions to modify the installer.
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-6228
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196478
|
7.5 |
HIGH
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, …
|
CWE-20 CWE-116
Improper Input Validation Improper Encoding or Escaping of Output
|
CVE-2020-6227
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196479
|
5.4 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence_platform
|
SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulner…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6226
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196480
|
6.2 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as passwords in trace file…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-6224
|
2024-11-21 14:35 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|