Vulnerabilities (CVE)

Filtered by CWE-79
Total 35377 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-2486 1 Sap 2 Marketing Sapscore, Marketing Uicuan 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2479 1 Sap 1 Businessobjects Bi Platform 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Business Intelligence Platform (BIWorkspace), versions 4.1 and 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2472 1 Sap 1 Businessobjects Bi Platform 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2470 1 Sap 1 Netweaver 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2466 1 Sap 1 Data Services 2024-11-21 3.5 LOW 5.4 MEDIUM
In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate user-controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2464 1 Sap 1 Netweaver 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2452 1 Sap 1 Netweaver Application Server Java 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability.
CVE-2018-2444 1 Sap 1 Businessobjects Financial Consolidation 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2435 1 Sap 1 Netweaver Enterprise Portal 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2432 1 Sap 1 Businessobjects Business Intelligence 2024-11-21 4.9 MEDIUM 5.4 MEDIUM
SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.
CVE-2018-2431 1 Sap 1 Businessobjects Business Intelligence 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2410 1 Sap 1 Business One 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2405 1 Sap 1 Solution Manager 2024-11-21 3.5 LOW 5.4 MEDIUM
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
CVE-2018-2399 1 Sap 1 Process Monitoring Infrastructure 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs.
CVE-2018-2397 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
CVE-2018-2388 1 Sap 1 Internet Graphics Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2018-2383 1 Sap 1 Internet Graphics Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2018-2371 1 Sap 1 Netweaver Java Web Application 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2365 1 Sap 1 Netweaver Portal 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-2364 1 Sap 2 Customer Relationship Management Webclient Ui, S4fnd 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.