CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
SAP NetWeaver AS ABAP Authorization Bypass Vulnerability in RFC Function Modules
A vulnerability exists in SAP NetWeaver AS ABAP and ABAP Platform, where authorization checks are not properly enforced for certain Remote Function Call (RFC) function modules. This flaw allows an attacker with basic user privileges to manipulate data in the Informix database, potentially leading to a complete compromise of confidentiality, integrity, and availability.
SAP BusinessObjects Business Intelligence Platform Session Hijacking Vulnerability
An information disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to hijack sessions over the network without user interaction. This vulnerability enables the attacker to access and modify all application data.
SAP BusinessObjects Business Intelligence Platform Cross-Site Scripting Vulnerability Allowing Data Theft and Impersonation
A cross-site scripting vulnerability has been identified in SAP BusinessObjects Business Intelligence Platform. This issue allows an authenticated user with limited access to inject malicious JavaScript that can read sensitive information from the server and send it to the attacker. The attacker could then use this information to impersonate a high-privileged user, significantly impacting the application's confidentiality and integrity.
SAP NetWeaver AS ABAP SAP GUI for HTML Local Storage Data Exposure Vulnerability
A vulnerability exists in applications using SAP GUI for HTML on SAP NetWeaver Application Server ABAP, where user input is stored in the local browser storage. This storage is accessible to attackers with administrative privileges or those who can access the victim's user directory at the operating system level. The exposed data, depending on the user input in transactions, could range from non-critical to highly sensitive, significantly impacting the application's confidentiality.
SAP Business Workflow and Flexible Workflow Sensitive Information Disclosure Vulnerability
A vulnerability exists in SAP Business Workflow and SAP Flexible Workflow, allowing authenticated attackers to manipulate parameters in legitimate resource requests. This manipulation can lead to unauthorized access to sensitive information that is normally restricted. However, the attackers cannot modify or disrupt the availability of the information.
SAP NetWeaver AS JAVA Stored Cross-Site Scripting Vulnerability in User Admin Application
A stored cross-site scripting vulnerability has been identified in the User Admin Application of SAP NetWeaver AS JAVA. This issue allows an attacker, impersonating an admin, to upload a photo containing malicious JavaScript. When a victim accesses the affected component, the injected script can be executed, potentially leading to unauthorized reading and modification of information within the victim's web browser.
SAP GUI for Java User Input Data Disclosure Vulnerability
A vulnerability exists in SAP GUI for Java that allows for the unauthorized reading of user input data saved on the client PC. This issue can be exploited by an attacker with administrative privileges or access to the victim's user directory at the Operating System level. The disclosed data, which could range from non-critical to highly sensitive depending on the user input in transactions, poses a significant risk to the application's confidentiality.
SAP GUI for Windows User Input Data Disclosure Vulnerability
A vulnerability exists in SAP GUI for Windows that allows for the unauthorized reading of user input data stored on the client PC. This issue arises under specific conditions, where an attacker with administrative privileges or access to the victim's user directory at the Operating System level could access the data. The impact of this vulnerability varies depending on the nature of the user input, potentially leading to the disclosure of either non-critical or highly sensitive information, thereby significantly compromising the application's confidentiality.
SAP NetWeaver Application Server for ABAP Unauthorized Access to System Information Vulnerability
A vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform allows unauthorized access to system information, including details like system configuration. This issue arises from a specific URL parameter that can be exploited by an unauthenticated attacker. While the vulnerability has a limited impact on confidentiality, it could be used to facilitate further attacks or exploits.
OpenLink Virtuoso Denial-of-Service Vulnerability in sqlg_group_node Component
A denial-of-service vulnerability has been identified in the sqlg_group_node component of OpenLink Virtuoso Open Source version 7.2.11. This issue allows attackers to disrupt service by executing crafted SQL statements that cause the application to crash.
OpenLink Virtuoso Denial-of-Service Vulnerability in sqlg_place_dpipes Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the sqlg_place_dpipes component, where attackers can cause a service disruption by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso-Opensource Denial-of-Service Vulnerability in SQLG Hash Source Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso-Opensource version 7.2.11. The issue arises in the SQLG hash source component, where attackers can cause a crash by sending crafted SQL statements. This vulnerability can be reproduced using the database management system's fuzzer, and it is also present in the beta Docker image of Virtuoso.
OpenLink Virtuoso SQL Injection Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in the OpenLink Virtuoso open-source version 7.2.11. The issue arises in the 'sqlo_df' component, where attackers can cause a service crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image by executing the malicious SQL through the isql command-line interface.
OpenLink Virtuoso SQL Injection Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the 'sqlo_expand_jts' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso Parallel SQL Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11, specifically within the 'sqlg_parallel_ts_seq' component. This issue allows attackers to disrupt service by executing crafted SQL statements that exploit the vulnerability.
OpenLink Virtuoso-Opensource Denial-of-Service Vulnerability in SQL Tree Hash Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso-Opensource version 7.2.11. The issue arises in the SQL tree hash component, where attackers can cause a service disruption by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso-OpenSource Denial-of-Service Vulnerability in SQL Vector Update Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso-OpenSource version 7.2.11. The issue arises in the 'sqlg_vec_upd' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image by executing the proof-of-concept SQL payload through the isql command-line interface.
OpenLink Virtuoso-OpenSource Denial-of-Service Vulnerability in SQL Distinct Node Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso-OpenSource version 7.2.11. The issue arises in the 'sqlc_add_distinct_node' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the beta Docker image of Virtuoso.
OpenLink Virtuoso Denial-of-Service Vulnerability in dfe_n_in_order Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the dfe_n_in_order component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the beta Docker image of Virtuoso 7.2.11.
Openlink Virtuoso-Opensource Denial-of-Service Vulnerability in QST_VEC_GET_INT64 Component
A denial-of-service vulnerability has been identified in Openlink Virtuoso-Opensource version 7.2.11. The issue arises in the 'qst_vec_get_int64' component, where attackers can cause a crash by executing crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
Openlink Virtuoso-Opensource Denial-of-Service Vulnerability in SQL Statement Processing
A denial-of-service vulnerability has been identified in Openlink Virtuoso-Opensource version 7.2.11. The issue arises in the 'qst_vec_set_copy' component, where attackers can cause a crash by executing crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso Numeric Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the numeric_to_dv component, where attackers can cause a service disruption by using specially crafted SQL statements. This vulnerability can be reproduced using the beta Docker image of Virtuoso 7.2.11.
OpenLink Virtuoso Denial-of-Service Vulnerability in jp_add Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the jp_add component, where attackers can cause a service disruption by sending crafted SQL statements. This vulnerability can be reproduced using the beta Docker image of Virtuoso 7.2.11.
OpenLink Virtuoso Denial-of-Service Vulnerability in SQL Statement Processing
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the 'qi_inst_state_free' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso-Opensource Denial-of-Service Vulnerability in QST Vector Set Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso-Opensource version 7.2.11. The issue arises in the QST vector set component, where attackers can cause a crash by executing crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso Denial-of-Service Vulnerability in itc_set_param_row Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the itc_set_param_row component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso Denial-of-Service Vulnerability in Row Insert Cast Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the row_insert_cast component, where attackers can cause a service disruption by using specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso Denial-of-Service Vulnerability in psiginfo Component
A denial-of-service vulnerability has been identified in the psiginfo component of OpenLink Virtuoso Open Source Edition, specifically in version 7.2.11. This issue allows attackers to cause a crash by executing crafted SQL statements. The vulnerability can be reproduced using the OpenLink Virtuoso Docker image.
OpenLink Virtuoso-OpenSource Denial-of-Service Vulnerability in SQL Statement Processing
A denial-of-service vulnerability has been identified in OpenLink Virtuoso-OpenSource version 7.2.11. The issue arises in the 'qi_inst_state_free' component, where attackers can cause a crash by executing crafted SQL statements. This vulnerability can be reproduced using the database management system's fuzzer, and it is also present in the beta Docker image of Virtuoso.
OpenLink Virtuoso Hash Comparison Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the 'itc_hash_compare' component, where attackers can cause a crash by sending specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image.
OpenLink Virtuoso-OpenSource Denial-of-Service Vulnerability in Version 7.2.11
A denial-of-service vulnerability has been identified in OpenLink Virtuoso-OpenSource version 7.2.11. The issue arises in the 'box_deserialize_string' component, where attackers can cause a crash by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image for version 7.2.11.
OpenLink Virtuoso Denial-of-Service Vulnerability in SQL Statement Processing Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the 'dfe_inx_op_col_def_table' component, where attackers can cause a crash by executing specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso database management system's built-in SQL execution interface.
OpenLink Virtuoso SQL Expression Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the SQL expression component of OpenLink Virtuoso Open Source version 7.2.11. This issue allows attackers to cause a crash by sending specially crafted SQL statements. The vulnerability can be reproduced using a proof-of-concept that exploits the SQL parser, leading to a stack smashing condition.
Openlink Virtuoso-Opensource Denial-of-Service Vulnerability in SQL Statement Processing
A denial-of-service vulnerability has been identified in Openlink Virtuoso-Opensource version 7.2.11. The issue arises in the 'dc_add_int' component, where attackers can cause a service disruption by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso database management system by executing a specific SQL update query that manipulates data in a way that crashes the database server.
Openlink Virtuoso-Opensource Denial-of-Service Vulnerability in SQL Processing Component
A denial-of-service vulnerability has been identified in Openlink Virtuoso-Opensource version 7.2.11. The issue arises in the 'dc_elt_size' component, where attackers can cause a crash by sending crafted SQL statements. This vulnerability can be reproduced using the Virtuoso Docker image version 7.2.11.
OpenLink Virtuoso Denial-of-Service Vulnerability in dfe_body_copy Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the dfe_body_copy component, where attackers can cause a service crash by executing specially crafted SQL statements. This vulnerability can be reproduced using the OpenLink Virtuoso Docker image.
OpenLink Virtuoso Denial-of-Service Vulnerability in dfe_unit_gb_dependant Component
A denial-of-service vulnerability has been identified in OpenLink Virtuoso Open Source version 7.2.11. The issue arises in the dfe_unit_gb_dependant component, where attackers can cause a service disruption by executing crafted SQL statements. This vulnerability can be reproduced using the beta Docker image of Virtuoso 7.2.11.
OpenLink Virtuoso Denial-of-Service Vulnerability in itc_sample_row_check Component
A denial-of-service vulnerability has been identified in the itc_sample_row_check component of OpenLink Virtuoso Open Source version 7.2.11. This issue allows attackers to cause a service disruption by executing crafted SQL statements that exploit the vulnerability.
Openlink Virtuoso-Opensource Denial-of-Service Vulnerability in SQL Processing Component
A denial-of-service vulnerability has been identified in Openlink Virtuoso-Opensource version 7.2.11. The issue arises in the 'chash_array' component, where attackers can cause a crash by executing specially crafted SQL statements. This vulnerability can be reproduced using the Virtuoso database management system by inserting a specific SQL payload that exploits the lack of proper argument checks in 'ORDER BY' and 'GROUP BY' clauses.
MonetDB Server Denial-of-Service Vulnerability in exp_copy Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1, specifically within the exp_copy component. This issue allows attackers to cause the server to crash by sending crafted SQL statements. The vulnerability can be reproduced in a Docker container running Ubuntu 20.04.
MonetDB Server Denial-of-Service Vulnerability in exps_bind_column Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the exps_bind_column component, where attackers can cause the server to crash by sending specially crafted SQL statements. This vulnerability can be reproduced by creating a specific SQL query that exploits the issue, leading to a crash of the MonetDB server process.
MonetDB Server Denial-of-Service Vulnerability in is_column_unique Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the is_column_unique component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by creating a table and executing specific SQL queries that manipulate column uniqueness, leading to a server crash.
MonetDB Server Denial-of-Service Vulnerability in exp_ref Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the exp_ref component, where attackers can cause the server to crash by sending specially crafted SQL statements. This vulnerability can be reproduced in a Docker environment using the MonetDB/MonetDB:Dec2023 image.
MonetDB Server Denial-of-Service Vulnerability in exps_card Component
A denial-of-service vulnerability has been identified in the exps_card component of MonetDB Server version 11.49.1. This issue allows attackers to cause the server to crash by sending crafted SQL statements. The vulnerability can be reproduced in a Docker environment using the MonetDB/MonetDB:Dec2023 image.
MonetDB Server Denial-of-Service Vulnerability in Tail Type Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the tail_type component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by executing a specific SQL query that exploits the group's handling within the query processing engine.
MonetDB Server Denial-of-Service Vulnerability in exp_values_set_supertype Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the exp_values_set_supertype component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by creating a merge table, adding a partition with specific values, and then executing the SQL commands, which triggers a server crash.
MonetDB Server Denial-of-Service Vulnerability in gc_col Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the gc_col component, where attackers can cause the server to crash by sending crafted SQL statements. This vulnerability can be reproduced by creating a merge table, starting a transaction, and then dropping specific columns, which triggers a server crash.
MonetDB Server Denial-of-Service Vulnerability in mat_join2 Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the mat_join2 component, where attackers can cause the server to crash by using specially crafted SQL statements. This vulnerability can be reproduced in a Docker environment using the official MonetDB image for December 2023.
MonetDB Server Denial-of-Service Vulnerability in Merge Table Prune and Unionize Component
A denial-of-service vulnerability has been identified in MonetDB Server version 11.49.1. The issue arises in the 'merge_table_prune_and_unionize' component, where attackers can cause the server to crash by using specially crafted SQL statements. This vulnerability can be reproduced in a Docker environment using the 'monetdb/monetdb:Dec2023' image.
MonetDB Server Denial-of-Service Vulnerability in exp_atom Component
A denial-of-service vulnerability has been identified in the exp_atom component of MonetDB Server version 11.49.1. This issue allows attackers to cause the server to crash by sending specially crafted SQL statements. The vulnerability can be reproduced in a Docker environment using the official MonetDB Docker image for the December 2023 release.
