Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Aug 13, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the...Show more |
1Sap 4Content Server Netweaver AbapNetweaver Java+1 moreJun 17, 2026 Aug 13, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Due to the missing authorization checks in the local systems, the admin users of SAP Web Dispatcher, SAP NetWeaver Application Server (ABAP and Java), and SAP Content Server can impersonate other users and may perform so...Show more |
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL a...Show more |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Aug 13, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can...Show more |
Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an attacker to get hold of the password and impersonate the affected user. As a result,...Show more |
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact o...Show more |
1Sap 2Business Warehouse Business Warehouse Virtual CompJun 17, 2026 Jul 9, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to...Show more |
1Sap 2Business Warehouse Business Warehouse Virtual CompJun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, a...Show more |
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the func...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP CRM WebClient does not
perform necessary authorization check for an authenticated user, resulting in
escalation of privileges. This could allow an attacker to access some sensitive
information. |
SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and a...Show more |
1Sap 2Saptmui Transportation ManagementJun 17, 2026 Jul 9, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a...Show more |
Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which might be downloaded and executed by the user which cou...Show more |
WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 7.7 HIGH· v3 N/A· v2 SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in informat...Show more |
SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities...Show more |
Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confi...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on co...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in t...Show more |
1Sap 1Netweaver Knowledge Management And Collaboration (kmc Cm) Jun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnera...Show more |