SAP SE / Netweaver Java Application Server
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-4158 | SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121661. | MEDIUM | 5.0 | Jun 2, 2015 |
| CVE-2015-2282 | Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver… | HIGH | 7.5 | Jun 2, 2015 |
| CVE-2015-2278 | The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netw… | MEDIUM | 5.0 | Jun 2, 2015 |
| CVE-2014-8590 | XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allows remote attackers to access arbitrary… | MEDIUM | 4.3 | Nov 4, 2014 |
| CVE-2014-3133 | SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered on an SLD v… | MEDIUM | 5.0 | Apr 30, 2014 |
Showing 1 to 5 of 5 CVEs