RSS   Vulnerabilities for 'Landscape management'   RSS

2020-04-14
 
CVE-2020-6236

CWE-269
 

 
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation.

 
2020-02-12
 
CVE-2020-6192

CWE-20
 

 
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.

 
 
CVE-2020-6191

CWE-20
 

 
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.

 
2019-10-08
 
CVE-2019-0380

CWE-532
 

 
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters? default values to be part of the application logs leading to Information Disclosure.

 
2019-02-15
 
CVE-2019-0261

CWE-287
 

 
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)).

 
2019-01-08
 
CVE-2019-0249

CWE-200
 

 
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted.

 

 >>> Vendor: SAP 283 Products
Sap r 3 web application server demo
Saposcol
Sap db
Sap r 3
Sapgui
Internet transaction server
Mysap business suite
Sap web application server
Business connector
Sapdba
Internet graphics server
Saplpd
Sapsprint
Rfc library
Sap basis component 640
Sap basis component 700
Netweaver nw04
Netweaver nw04s
Enjoysap
Internet communication manager
Sap message server
Business objects
Maxdb
Netweaver
Web dynpro
Sap gui
Tabone
Crystal reports server
Sap kernel
Business one 2005-a
Businessobjects
J2ee engine core
Server core
Crystal reports
System landscape directory
Netweaver business client
Netweaver abap
GUI
Production planning and control
Healthcare industry solution
Erp cental component
Basis communication services
Erp central component
Network interface router
Netweaver logviewer
Netweaver development infrastructure
Customer relationship management
Emr unwired
Netweaver solution manager
Netweaver exchange infrastructure (bc-xi)
Bi universal data integration
Ccms / database monitor
J2ee engine
Guided procedures archive monitor
Mobile infrastructure
Adminadapter
Cm services
Cms services
Ccms agent
Solution manager
Enterprise portal
Software deployment manager
Enhancement package
HANA
Print and output management
Business object processing framework for abap
Router
Netweaver software lifecycle manager
Netweaver abap application server
Profile maintenance
Background processing
Netweaver java application server
Project system
Brazil
Web services tool
Computing center management system monitoring
Transaction data pool
Capacity leveling
Open hub service
Oil industry solution traders and schedulers workbench
Upgrade tools
Supplier relationship management
Hana extend application services
Netweaver business warehouse
Fi manager self-service
Businessobjects xi
Businessobjects explorer
Adaptive server enterprise
Commoncryptolib
Sapcrytolib
Sapseculib
Environment health and safety
Document management services
Customer relationship management internet sales
Payroll process
Business intelligence development workbench
Hana web-based development workbench
Contract accounting
Governance risk and compliance
Sql anywhere
See all Products for Vendor SAP


Copyright 2020, cxsecurity.com

 

Back to Top