CVE-2023-39436 – Information Disclosure in SAP Supplier Relationship Management
https://notcve.org/view.php?id=CVE-2023-39436
SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication functionality.This information could be used to allow the attacker to specialize their attacks against SRM. • https://me.sap.com/notes/2067220 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-306: Missing Authentication for Critical Function •
CVE-2019-0361
https://notcve.org/view.php?id=CVE-2019-0361
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, versiones anteriores a 3.73, 7.31, 7.32) no codifica suficientemente las entradas controladas por el usuario, resultando en vulnerabilidad de tipo Cross-Site Scripting (XSS). • https://launchpad.support.sap.com/#/notes/2820607 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=525962506 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-2449
https://notcve.org/view.php?id=CVE-2018-2449
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying. SAP SRM MDM Catalog en versiones 3.73, 7.31 y 7.32 en (SAP NetWeaver 7.3) - la funcionalidad de importación no realiza comprobaciones de autenticación para los usuarios válidos del repositorio. Esta es una funcionalidad no autenticada que puede emplearse en equipos Windows para realizar retransmisiones SMB. • http://www.securityfocus.com/bid/105079 https://launchpad.support.sap.com/#/notes/2655250 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 • CWE-287: Improper Authentication •
CVE-2018-2448
https://notcve.org/view.php?id=CVE-2018-2448
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted. En ciertas condiciones, SAP SRM-MDM (CATALOG en versiones 3.0, 7.01 y 7.02) utiliza funcionalidades que permiten que un atacante acceda a información de usuarios que normalmente estaría restringida. • http://www.securityfocus.com/bid/105077 https://launchpad.support.sap.com/#/notes/2653846 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742 •
CVE-2014-4161
https://notcve.org/view.php?id=CVE-2014-4161
Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter. Vulnerabilidad de XSS en la/umTestSSO.jsp en SAP Supplier Relationship Management (SRM) permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro url. • http://blog.emaze.net/2014/05/sap-multiple-vulnerabilities.html http://scn.sap.com/docs/DOC-8218 http://secunia.com/advisories/58889 https://service.sap.com/sap/support/notes/1946420 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •