Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Process Integration Nov 21, 2024 Jun 12, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50) do not restrict or incorrectly restrict frame objects or UI layers that be...Show more |
1Sap 5Advanced Business Application Programming Platform Kernel Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 moreNov 21, 2024 Jun 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT...Show more |
Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identity Management REST Interface Version 2, which would otherwise be restricted only for viewing. |
SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Fixed in the following components SAP-CRMJAV SAP-CRMWEB SAP-SH...Show more |
1Sap 1Sap Solution Manager System Nov 21, 2024 May 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to access information on RFC destinations on managed systems and SAP Solution Manager system (ST-PI, b...Show more |
Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted. |
Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted. |
Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted. |
1Sap 1Treasury And Risk Management Nov 21, 2024 May 14, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_D...Show more |
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker. |
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML E...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 10, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML signatures and send arbitrary requests...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like relea...Show more |
1Sap 1Business Application Software Integrated Solution Nov 21, 2024 Apr 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 10, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database t...Show more |
1Sap 1Hana Extended Application Services Nov 21, 2024 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). |
1Sap 2Banking Services From Sap S/4hana Financial Products SubledgerNov 21, 2024 Mar 12, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorization check for an authenticated user, potentially resulting in escalation...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Mar 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site...Show more |
SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service (i.e. denial of service). Fixed in versions 3.1 SP03 PL02, SDK 3.1 SP04, or late...Show more |
1Sap 3Advanced Business Application Programming Platform Advanced Business Application Programming ServerSap KernelNov 21, 2024 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.2...Show more |