2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-6215MEDIUM6.1SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752,...
CVE-2020-6211MEDIUM6.1SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect user...
CVE-2020-6195CRITICAL9.8SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, l...
CVE-2020-11723MEDIUM5.5Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target device...
CVE-2020-6238CRITICAL9.3SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xy...
CVE-2020-6237HIGH7.5Under certain conditions, SAP Business Objects Business Intelligence Platform, version 4.1, 4.2, dswsbobje web applicati...
CVE-2020-6236HIGH7.2SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group pri...
CVE-2020-6235HIGH8.6SAP Solution Manager (Diagnostics Agent), version 7.2, does not perform the authentication check for the functionalities...
CVE-2020-6234HIGH7.2SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privi...
CVE-2020-6233MEDIUM4.3SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows...
CVE-2020-6232MEDIUM5.3SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing...
CVE-2020-6231MEDIUM5.4SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficientl...
CVE-2020-6230HIGH7.2SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that ca...
CVE-2020-6229MEDIUM6.1SAP NetWeaver AS ABAP (Business Server Pages application CRM_BSP_FRAME), versions 700, 701, 702, 710, 711, 730, 731, 740...
CVE-2020-6228HIGH7.5SAP Business Client, versions 6.5, 7.0, does not perform necessary integrity checks which could be exploited by an attac...
CVE-2020-6227HIGH7.5SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specia...
CVE-2020-6226MEDIUM5.4SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), version 4.2, does not sufficientl...
CVE-2020-6224MEDIUM6.2SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with adminis...
CVE-2020-6223MEDIUM6.1The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modif...
CVE-2020-6222MEDIUM5.4SAP Business Objects Business Intelligence Platform (Web Intelligence HTML interface), versions 4.1, 4.2, does not suffi...
CVE-2020-6221MEDIUM5.4Web Intelligence HTML interface in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not suff...
CVE-2020-6219HIGH8.8SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Repo...
CVE-2020-6218MEDIUM5Admin tools and Query Builder in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attac...
CVE-2020-6216MEDIUM6.1SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-contr...
CVE-2020-6214MEDIUM4.7SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Althoug...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now