Security News

CVE-2018-2393

National Vulnerability Database - Wed, 02/14/2018 - 07:29
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
Categories: Security News

CVE-2018-2394

National Vulnerability Database - Wed, 02/14/2018 - 07:29
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.
Categories: Security News

CVE-2018-2395

National Vulnerability Database - Wed, 02/14/2018 - 07:29
Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.
Categories: Security News

CVE-2018-2396

National Vulnerability Database - Wed, 02/14/2018 - 07:29
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service.
Categories: Security News

CVE-2018-2364

National Vulnerability Database - Wed, 02/14/2018 - 07:29
SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.
Categories: Security News

CVE-2018-2369

National Vulnerability Database - Wed, 02/14/2018 - 07:29
Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.
Categories: Security News

CVE-2018-2370

National Vulnerability Database - Wed, 02/14/2018 - 07:29
Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user to use common techniques to determine which ports are in use on the backend server.
Categories: Security News

CVE-2018-2371

National Vulnerability Database - Wed, 02/14/2018 - 07:29
The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.
Categories: Security News

CVE-2018-2372

National Vulnerability Database - Wed, 02/14/2018 - 07:29
A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.
Categories: Security News

CVE-2018-2373

National Vulnerability Database - Wed, 02/14/2018 - 07:29
Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0.
Categories: Security News

CVE-2018-2374

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space.
Categories: Security News

CVE-2018-2375

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.
Categories: Security News

CVE-2018-2376

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.
Categories: Security News

CVE-2018-2377

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.
Categories: Security News

CVE-2018-2378

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption.
Categories: Security News

CVE-2018-2379

National Vulnerability Database - Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
Categories: Security News

CVE-2018-2381

National Vulnerability Database - Wed, 02/14/2018 - 07:29
SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Categories: Security News

CVE-2018-2382

National Vulnerability Database - Wed, 02/14/2018 - 07:29
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled area and as such gain information from system area, which is not available to the user otherwise.
Categories: Security News

Vuln: Jenkins CVE-2018-6356 Directory Traversal Vulnerability

SecurityFocus Vulnerabilities - Wed, 02/14/2018 - 00:00
Jenkins CVE-2018-6356 Directory Traversal Vulnerability
Categories: Security News

Vuln: Dell EMC Isilon OneFS Multiple Security Vulnerabilities

SecurityFocus Vulnerabilities - Wed, 02/14/2018 - 00:00
Dell EMC Isilon OneFS Multiple Security Vulnerabilities
Categories: Security News

Pages