CVEs (86)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 9Commoncryptolib Content ServerExtended Application Services And Runtime+6 moreNov 21, 2024 Sep 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the applicati...Show more |
1Sap 9Commoncryptolib Content ServerExtended Application Services And Runtime+6 moreNov 21, 2024 Sep 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it u...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Jul 11, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERN...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Apr 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can...Show more |
1Sap 2Netweaver Netweaver Application Server AbapNov 21, 2024 Apr 11, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 9.6 CRITICAL· v3 N/A· v2 SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, th...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 9.6 CRITICAL· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a director...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can cr...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application o...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privile...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspe...Show more |
1Sap 4Netweaver Application Server Abap Netweaver Application Server Abap KernelNetweaver Application Server Abap Krnl64nuc+1 moreNov 21, 2024 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KR...Show more |