Sap Se Sap Landscape Management vulnerabilities
5 known vulnerabilities affecting sap_se/sap_landscape_management.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-39593MEDIUMCVSS 5.7vVCM 3.002024-07-09
CVE-2024-39593 [MEDIUM] CWE-200 CVE-2024-39593: SAP Landscape Management allows an authenticated
user to read confidential data disclosed by the RES
SAP Landscape Management allows an authenticated
user to read confidential data disclosed by the REST Provider Definition
response. Successful exploitation can cause high impact on confidentiality of
the managed entities.
cvelistv5nvd
CVE-2020-6236HIGHCVSS 7.2fixed in 3.02020-04-14
CVE-2020-6236 [HIGH] CWE-269 CVE-2020-6236: SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation.
cvelistv5nvd
CVE-2020-6192HIGHCVSS 7.2v= 3.02020-02-12
CVE-2020-6192 [HIGH] CWE-20 CVE-2020-6192: SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.
cvelistv5nvd
CVE-2020-6191HIGHCVSS 7.2v= 3.02020-02-12
CVE-2020-6191 [HIGH] CWE-20 CVE-2020-6191: SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.
cvelistv5nvd
CVE-2019-0249HIGHCVSS 7.5fixed in 3.02019-01-08
CVE-2019-0249 [HIGH] CVE-2019-0249: Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted.
cvelistv5nvd