Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Abap Platform
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6310 1 Sap 2 Abap Platform, Netweaver As Abap 2021-07-21 4.0 MEDIUM 4.3 MEDIUM
Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Information Disclosure.
CVE-2020-6299 1 Sap 2 Abap Platform, Netweaver As Abap 2021-07-21 4.0 MEDIUM 4.3 MEDIUM
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure.
CVE-2020-6181 1 Sap 2 Abap Platform, Netweaver 2020-02-21 5.0 MEDIUM 5.8 MEDIUM
Under some circumstances the SAML SSO implementation in the SAP NetWeaver (SAP_BASIS versions 702, 730, 731, 740 and SAP ABAP Platform (SAP_BASIS versions 750, 751, 752, 753, 754), allows an attacker to include invalidated data in the HTTP response header sent to a Web user, leading to HTTP Response Splitting vulnerability.