Latest CVE Feed
-
5.5
MEDIUMCVE-2021-27638
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated JT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caus... Read more
Affected Products : 3d_visual_enterprise_viewer- EPSS Score: %0.14
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27637
Under certain conditions SAP Enable Now (SAP Workforce Performance Builder - Manager), versions - 1.0, 10 allows an attacker to access information which would otherwise be restricted leading to information disclosure.... Read more
Affected Products : enable_now- EPSS Score: %0.06
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-27635
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerabi... Read more
Affected Products : netweaver_application_server_for_java- EPSS Score: %2.08
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27634
SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without spe... Read more
Affected Products : netweaver_abap- EPSS Score: %0.21
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27633
SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without spe... Read more
Affected Products : netweaver_abap- EPSS Score: %0.28
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27632
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without sp... Read more
Affected Products : netweaver_as_abap- EPSS Score: %0.32
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27631
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without sp... Read more
Affected Products : netweaver_as_abap- EPSS Score: %0.32
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27630
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without sp... Read more
Affected Products : netweaver_as_abap- EPSS Score: %0.32
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27629
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without sp... Read more
Affected Products : netweaver_as_abap- EPSS Score: %0.28
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-27628
SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allo... Read more
Affected Products : netweaver_as_abap- EPSS Score: %0.28
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27627
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in m... Read more
Affected Products : netweaver_as_internet_graphics_server- EPSS Score: %0.51
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27626
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in m... Read more
Affected Products : netweaver_as_internet_graphics_server- EPSS Score: %0.51
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27625
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in m... Read more
Affected Products : netweaver_as_internet_graphics_server- EPSS Score: %0.51
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27624
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in m... Read more
Affected Products : netweaver_as_internet_graphics_server- EPSS Score: %0.51
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27623
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in m... Read more
Affected Products : netweaver_as_internet_graphics_server- EPSS Score: %0.27
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27622
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in m... Read more
Affected Products : netweaver_as_internet_graphics_server- EPSS Score: %0.51
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-27621
Information Disclosure vulnerability in UserAdmin application in SAP NetWeaver Application Server for Java, versions - 7.11,7.20,7.30,7.31,7.40 and 7.50 allows attackers to access restricted information by entering malicious server name.... Read more
- EPSS Score: %0.22
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-27620
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in m... Read more
Affected Products : netweaver_as_internet_graphics_server- EPSS Score: %0.51
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-27619
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one cha... Read more
Affected Products : commerce- EPSS Score: %0.18
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-27618
The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a malicious file and upload it to the ... Read more
Affected Products : netweaver_process_integration- EPSS Score: %0.21
- Published: May. 11, 2021
- Modified: Nov. 21, 2024