Page 2 of 8 results (0.005 seconds)

CVSS: 6.1EPSS: 0%CPEs: 7EXPL: 0

Cross-Site scripting (XSS) in SAP Business Warehouse Universal Data Integration, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to insufficient encoding of user controlled inputs. Cross-Site scripting (XSS) en SAP Business Warehouse Universal Data Integration, desde la versión 7.10 hasta la 7.11, 7.20, 7.30, 7.31, 7.40 y 7.50, debido a la codificación insuficiente de entradas controladas por el usuario. • http://www.securityfocus.com/bid/102148 https://blogs.sap.com/2017/12/12/sap-security-patch-day-december-2017 https://launchpad.support.sap.com/#/notes/2537545 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en Data Basis (BW-WHM-DBA) en SAP NetWeaver Business Warehouse permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de vectores no especificados. • http://blog.onapsis.com/analyzing-sap-security-notes-october-2014-edition http://service.sap.com/sap/support/notes/0001965819 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 3.5EPSS: 0%CPEs: 1EXPL: 0

The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors. El componente SAP Netweaver Business Warehouse no restringe debidamente el acceso a las funciones en el grupo de funciones BW-SYS-DB-DB4, lo que permite a usuarios remotos autenticados obtener información sensible a través de vectores no especificados. • http://packetstormsecurity.com/files/127671/SAP-Netweaver-Business-Warehouse-Missing-Authorization.html http://scn.sap.com/docs/DOC-8218 http://seclists.org/fulldisclosure/2014/Jul/154 http://secunia.com/advisories/59635 http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-026 http://www.securityfocus.com/bid/68955 https://exchange.xforce.ibmcloud.com/vulnerabilities/94921 https://service.sap.com/sap/support/notes/1974016 • CWE-264: Permissions, Privileges, and Access Controls •