6 results (0.004 seconds)

CVSS: 5.8EPSS: 0%CPEs: 8EXPL: 0

SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM. • https://me.sap.com/notes/2067220 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-306: Missing Authentication for Critical Function •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, versiones anteriores a 3.73, 7.31, 7.32) no codifica suficientemente las entradas controladas por el usuario, resultando en vulnerabilidad de tipo Cross-Site Scripting (XSS). • https://launchpad.support.sap.com/#/notes/2820607 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=525962506 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.6EPSS: 0%CPEs: 3EXPL: 0

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying. SAP SRM MDM Catalog en versiones 3.73, 7.31 y 7.32 en (SAP NetWeaver 7.3) - la funcionalidad de importación no realiza comprobaciones de autenticación para los usuarios válidos del repositorio. Esta es una funcionalidad no autenticada que puede emplearse en equipos Windows para realizar retransmisiones SMB. • http://www.securityfocus.com/bid/105079 https://launchpad.support.sap.com/#/notes/2655250 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-287: Improper Authentication •

CVSS: 5.3EPSS: 0%CPEs: 3EXPL: 0

Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted. En ciertas condiciones, SAP SRM-MDM (CATALOG en versiones 3.0, 7.01 y 7.02) utiliza funcionalidades que permiten que un atacante acceda a información de usuarios que normalmente estaría restringida. • http://www.securityfocus.com/bid/105077 https://launchpad.support.sap.com/#/notes/2653846 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter. Vulnerabilidad de XSS en la/umTestSSO.jsp en SAP Supplier Relationship Management (SRM) permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro url. • http://blog.emaze.net/2014/05/sap-multiple-vulnerabilities.html http://scn.sap.com/docs/DOC-8218 http://secunia.com/advisories/58889 https://service.sap.com/sap/support/notes/1946420 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •