|
194941
|
6.1 |
MEDIUM
Network
|
sap
|
web_dynpro_abap
|
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
|
CWE-601
Open Redirect
|
CVE-2021-21478
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194942
|
9.9 |
CRITICAL
Network
|
sap
|
commerce
|
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject mali…
|
CWE-94
Code Injection
|
CVE-2021-21477
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194943
|
6.1 |
MEDIUM
Network
|
sap
|
ui5
|
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerab…
|
CWE-601
Open Redirect
|
CVE-2021-21476
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194944
|
7.5 |
HIGH
Network
|
sap
|
netweaver_master_data_management_server
|
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus charac…
|
CWE-22
Path Traversal
|
CVE-2021-21475
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194945
|
6.5 |
MEDIUM
Network
|
sap
|
hana_database
|
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tam…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-21474
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194946
|
8.8 |
HIGH
Network
|
sap
|
software_provisioning_manager
|
SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perfo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-21472
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194947
|
6.1 |
MEDIUM
Network
|
sap
|
businessobjects_business_intelligence
|
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This coul…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-21444
|
2024-11-21 14:48 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194948
|
4.3 |
MEDIUM
Network
|
otrs
|
cis_in_customer_frontend
|
Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-21436
|
2024-11-21 14:48 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194949
|
6.5 |
MEDIUM
Network
|
otrs
|
otrs
|
Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0…
|
CWE-200
Information Exposure
|
CVE-2021-21435
|
2024-11-21 14:48 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194950
|
4.8 |
MEDIUM
Network
|
otrs
|
survey
|
Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. another agent who wants to make changes in the survey). This issue affects: OTRS A…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21434
|
2024-11-21 14:48 |
2021-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|