Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Netweaver Abap
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1309 1 Sap 1 Netweaver Abap 2018-12-10 5.0 MEDIUM N/A
XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.
CVE-2014-8312 1 Sap 1 Netweaver Abap 2018-10-09 3.5 LOW N/A
Business Warehouse (BW) in SAP Netweaver AS ABAP 7.31 allows remote authenticated users to obtain sensitive information via a request to the RSDU_CCMS_GET_PROFILE_PARAM RFC function.
CVE-2012-4341 1 Sap 1 Netweaver Abap 2018-08-13 10.0 HIGH N/A
Multiple stack-based buffer overflows in msg_server.exe in SAP NetWeaver ABAP 7.x allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) long parameter value, (2) crafted string size field, or (3) long Parameter Name string in a package with opcode 0x43 and sub opcode 0x4 to TCP port 3900.