Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Diagnostics Agent
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0330 1 Sap 1 Diagnostics Agent 2023-12-19 6.5 MEDIUM 9.1 CRITICAL
The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
CVE-2019-0390 1 Sap 1 Diagnostics Agent 2019-11-15 4.0 MEDIUM 4.3 MEDIUM
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.