VendorsSAPlandscape_management3.0
Vulnerabilities

SAP Landscape Management 3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2019-0261
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for stack)).
Published 2019-02-15 · Modified
9.8EPSS 0.036
CVE-2020-6192
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.
Published 2020-02-12 · Modified
9.0EPSS 0.017
CVE-2020-6191
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation.
Published 2020-02-12 · Modified
9.0EPSS 0.016
CVE-2023-26458
Information Disclosure vulnerability in SAP Landscape Management
Published 2023-04-11 · Modified
8.7EPSS 0.006
CVE-2019-0249
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted.
Published 2019-01-08 · Modified
7.5EPSS 0.017
CVE-2020-6236
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation.
Published 2020-04-14 · Modified
7.2EPSS 0.012
CVE-2024-39593
[CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management
Published 2024-07-09 · Modified
6.9EPSS 0.003
CVE-2019-0380
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure.
Published 2019-10-08 · Modified
4.9EPSS 0.009