SAP AG

Short Name: SAP
Previous Names: [None Entered]
URL: http://www.sap.com/ [visit link]
Email: infosap.com
Security URL: http://www.sap.com/security [visit link]
Security Email: securesap.com
Knowledge Base: http://service.sap.com/notes [visit link]
Notes: Contact web form: http://www.sap.com/contactsap/ KB Requires Authentication

Vulnerabilities by Vendor Product

SAP AG

SAP AG
Enterprise Portal Watch-list
Unspecified
Unspecified
EnjoySAP Watch-list
Unspecified
OSVDB ID: 37690 EnjoySAP SAP GUI kweditcontrol.kwedit.1 ActiveX (kwedit.dll) PrepareToPostHTML Function Arbitrary Code Execution
ERP Central Component (ECC) Watch-list
Unspecified
OSVDB ID: 93074 SAP ERP Central Component (ECC) Remote Function Module Multiple Call Handling Remote Code Execution
BusinessObjects Financial Consolidation Watch-list
Unspecified
OSVDB ID: 84826 SAP BusinessObjects Financial Consolidation CtAppReg.dll Check Function Username Parsing Remote Overflow
Business One Watch-list
2005-A
OSVDB ID: 56837 SAP Business One License Manager (NT_Naming_Service.exe) GIOP Request Remote Overflow
BusinessObjects Enterprise Watch-list
XI 3.2
OSVDB ID: 68678 SAP BusinessObjects Dswsbobje dswsbobje/services/session URI Login SOAPAction Account Name Enumeration
OSVDB ID: 68679 SAP BusinessObjects dswsbobje/services/biplatform URI GenerateCuids SOAPAction numCuids Value Remote DoS
OSVDB ID: 68680 SAP BusinessObjects Edit Service Parameters Page ServiceClass Field XSS
OSVDB ID: 68681 SAP BusinessObjects CrystalReports/viewrpt.cwr URI apstoken Parameter TCP Connection Remote Information Disclosure
OSVDB ID: 68682 SAP BusinessObjects CmcApp Multiple Property Remote Privilege Escalation
OSVDB ID: 68662 Apache Axis2 dswsbobje.war Module Admin Account Default Password
Crystal Reports Server Watch-list
2008
OSVDB ID: 68660 SAP BusinessObjects Crystal Reports CMS.exe GIOP Request Remote Overflow
OSVDB ID: 68661 SAP BusinessObjects Crystal Reports JobServer.exe GIOP Request Remote Overflow
OSVDB ID: 71123 SAP Crystal Reports Server aa-add-analytic2.jsp backURL Parameter XSS
OSVDB ID: 71124 SAP Crystal Reports Server aa-add-validate.jsp pagePos Parameter XSS
OSVDB ID: 71125 SAP Crystal Reports Server aa-analytic-frameset.jsp entry Parameter XSS
OSVDB ID: 71126 SAP Crystal Reports Server aa-cacheparams.jsp Multiple Parameter XSS
OSVDB ID: 71127 SAP Crystal Reports Server aa-display-flash.jsp swf Parameter XSS
OSVDB ID: 71128 SAP Crystal Reports Server aa-dmgraph.jsp Sel Parameter XSS
OSVDB ID: 71129 SAP Crystal Reports Server aa-edit-goal.jsp defTar Parameter XSS
OSVDB ID: 71130 SAP Crystal Reports Server aa-map-frameset.jsp analyticToken Parameter XSS
OSVDB ID: 71131 SAP Crystal Reports Server aa-open-inlist.jsp Multiple Parameter XSS
OSVDB ID: 71132 SAP Crystal Reports Server aa-overviewctxt.jsp Multiple Parameter XSS
OSVDB ID: 72427 SAP Crystal Reports Server InfoView Module logon.jsp logonAction Parameter XSS
OSVDB ID: 72425 SAP Crystal Reports Server InfoView Module actionNav.jsp actId Parameter XSS
2008
2008
2008
2008
2008
2008
2008
2008
2008
2008
2008
2008
OSVDB ID: 72426 SAP Crystal Reports Server InfoView Module error.jsp backUrl Parameter XSS
2008
Business Objects InfoVew System Watch-list
XI R2
OSVDB ID: 80638 SAP Business Objects InfoVew System listing.aspx searchText Parameter XSS
Exchange Infrastructure Watch-list
3.0
OSVDB ID: 92702 SAP NetWeaver Portal com.sap.portal.support.browse.default Unspecified Traversal Arbitrary File Access
Crystal Reports Watch-list
2008 SP3 Fix Pack 3.2
OSVDB ID: 69917 SAP Crystal Reports CrystalReports12.CrystalPrintControl.1 ActiveX ServerResourceVersion Property Overflow
2008 12.x
OSVDB ID: 68660 SAP BusinessObjects Crystal Reports CMS.exe GIOP Request Remote Overflow
OSVDB ID: 68661 SAP BusinessObjects Crystal Reports JobServer.exe GIOP Request Remote Overflow
2011
OSVDB ID: 84841 SAP Crystal Reports ebus-3-3-2-7.dll crystalras.exe GIOP ORB Data Copying Remote Overflow
2008
OSVDB ID: 92738 SAP Crystal Reports 2008 MessagingSystem Multiple Unspecified XSS



The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use