CVE-2019-0279
- EPSS 0.34%
- Veröffentlicht 10.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:16:37
ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary authorization checks in all c...
- EPSS 0.29%
- Veröffentlicht 11.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:55
Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.
CVE-2018-2367
- EPSS 1.81%
- Veröffentlicht 01.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:41
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to paren...
CVE-2018-2363
- EPSS 0.74%
- Veröffentlicht 09.01.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:40
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the syst...
CVE-2017-16682
- EPSS 0.55%
- Veröffentlicht 12.12.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavi...
CVE-2017-16691
- EPSS 0.37%
- Veröffentlicht 12.12.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note ...