Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
- EPSS 25.93%
- Published 09.03.2021 15:15:14
- Last modified 05.05.2025 17:16:58
SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forward to server. When this dashb...
8.8
CVE-2019-0267
- EPSS 0.2%
- Published 15.02.2019 18:29:02
- Last modified 21.11.2024 04:16:36
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Servlet from an external applicat...
- EPSS 0.15%
- Published 24.11.2015 20:59:24
- Last modified 12.04.2025 10:46:40
SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.
1