CVE-2024-30214
- EPSS 0.15%
- Veröffentlicht 09.04.2024 01:15:49
- Zuletzt bearbeitet 21.11.2024 09:11:27
The application allows a high privilege attacker to append a malicious GET query parameter to Service invocations, which are reflected in the server response. Under certain circumstances, if the parameter contains a JavaScript, the script could be pr...
CVE-2024-30215
- EPSS 0.15%
- Veröffentlicht 09.04.2024 01:15:49
- Zuletzt bearbeitet 21.11.2024 09:11:27
The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whenever a User visits the page. In a successful attack, some information could be obtained and/or modified. However, the attacker does...
- EPSS 6.02%
- Veröffentlicht 16.02.2006 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.
CVE-2006-0732
- EPSS 3.08%
- Veröffentlicht 16.02.2006 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in SAP Business Connector (BC) 4.6 and 4.7 allows remote attackers to read or delete arbitrary files via the fullName parameter to (1) sapbc/SAP/chopSAPLog.dsp or (2) invoke/sap.monitor.rfcTrace/deleteSingle. Detail...