CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Supplier Relationship Management Jun 17, 2026 Jan 13, 2026 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an att...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 Sep 9, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim click...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. Th...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which wh...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the v...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 Aug 8, 2023 N/A· v4 5.8 MEDIUM· v3 N/A· v2 SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication f...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 Sep 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabi...Show more |
1Sap 1Supplier Relationship Management May 6, 2026 Jun 13, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter. |
1Sap 1Supplier Relationship Management May 6, 2026 Jun 13, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parame...Show more |