6.3

CVSS3.1

CVE-2024-47595 - Local Privilege Escalation in SAP Host Agent

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.

πŸ“… Published: Nov. 12, 2024, 12:27 a.m. πŸ”„ Last Modified: Nov. 14, 2024, 3:21 p.m.

4.3

CVSS3.1

CVE-2024-47593 - Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or d…

πŸ“… Published: Nov. 12, 2024, 12:27 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 3:35 p.m.

5.3

CVSS3.1

CVE-2024-47592 - Information Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application)

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.

πŸ“… Published: Nov. 12, 2024, 12:27 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 1:55 p.m.

8.8

CVSS3.1

CVE-2024-47590 - Cross-Site Scripting (XSS) vulnerability in SAP Web Dispatcher

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to a…

πŸ“… Published: Nov. 12, 2024, 12:26 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 5:11 p.m.

4.7

CVSS3.1

CVE-2024-47588 - Information Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager)

In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the …

πŸ“… Published: Nov. 12, 2024, 12:26 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 8:13 p.m.

3.5

CVSS3.1

CVE-2024-47587 - Missing authorization check in SAP Cash Management (Cash Operations)

Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.

πŸ“… Published: Nov. 12, 2024, 12:26 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 8:13 p.m.

5.3

CVSS3.1

CVE-2024-47586 - NULL Pointer Dereference vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platfo…

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporari…

πŸ“… Published: Nov. 12, 2024, 12:25 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 5:14 p.m.

6.5

CVSS3.1

CVE-2024-42372 - Missing Authorization check in SAP NetWeaver AS Java (System Landscape Directory)

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.

πŸ“… Published: Nov. 12, 2024, 12:25 a.m. πŸ”„ Last Modified: Nov. 12, 2024, 1:55 p.m.

6.6

CVSS3.1

CVE-2024-28728 -

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via a crafted payload to the WiFi SSID Name field.

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: July 13, 2025, 11:14 a.m.

6.1

CVSS3.1

CVE-2021-27703 -

Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.

πŸ“… Published: Nov. 12, 2024, midnight πŸ”„ Last Modified: Nov. 15, 2024, 10:35 p.m.
Total resulsts: 344142
Page 7436 of 34,415
Β« previous page Β» next page
Filters