Home/Product/sap content server
Product

sap content server

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-33005
all versions
Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Ser
6.3MEDIUM
CVE-2023-40309
all versions
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks fo
9.8CRITICAL
CVE-2023-40308
all versions
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory c
7.5HIGH
CVE-2023-26457
all versions
SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vu
6.1MEDIUM
CVE-2022-22536
all versions
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web D
10.0CRITICAL
CVE-2021-3010
all versions
There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 2
5.4MEDIUM
CVE-2015-4157
all versions
SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Sec
CVE-2007-3018
<= 5.6.2929
activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, whic
CVE-2007-3017
<= 5.6.2929
The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/a
CVE-2007-3014
<= 5.6.2929
Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject ar
CVE-2007-3013
<= 5.6.2929
SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to e
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin