Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sap afaria - vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2015-4161
SAP Afaria does not properly restrict access to unspecified functionality, which allows remote malicious users to obtain sensitive information, gain privileges, or have other unspecified impact via unknown vectors, SAP Security Note 2155690.
Sap Afaria -
9.1
CVSSv3
CVE-2015-8753
SAP Afaria 7.0.6001.5 allows remote malicious users to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.
Sap Afaria 7.0.6001.5
NA
CVE-2015-2816
The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote malicious users to have unspecified impact via a crafted request, aka SAP Security Note 2134905.
Sap Afaria 7.0.6001.5
NA
CVE-2015-2820
Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote malicious users to cause a denial of service (process termination) via a crafted request, aka SAP Security Note 2132584.
Sap Afaria 7.0.6001.5
NA
CVE-2015-4092
Buffer overflow in the XComms process in SAP Afaria 7.00.6620.2 SP5 allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, aka SAP Security Note 2153690.
Sap Afaria 7.0.6620.2
NA
CVE-2015-3449
The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService.exe file.
Sap Afaria 7.0.6398.0
NA
CVE-2015-6663
Cross-site scripting (XSS) vulnerability in the Client form in the Device Inspector page in SAP Afaria 7 allows remote malicious users to inject arbitrary web script or HTML via crafted client name data, aka SAP Security Note 2152669.
Sap Afaria 7.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started