Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 5Advanced Business Application Programming Platform Kernel Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 moreNov 21, 2024 Mar 12, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC...Show more |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Mar 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Mar 12, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source. |
1Sap 1Manufacturing Integration And Intelligence Nov 21, 2024 Feb 15, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Ser...Show more |
1Sap 1Hana Extended Application Services Nov 21, 2024 Feb 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is prote...Show more |
1Sap 5Advanced Business Application Programming Platform Kernel Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 moreNov 21, 2024 Feb 15, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Fixed in versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT,KRNL32UC 7.2...Show more |
1Sap 1Businessobjects Bi Platform Nov 21, 2024 Feb 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability. |
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (ru...Show more |
SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation. |
SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
1Sap 2Netweaver Application Server Abap Netweaver As AbapNov 21, 2024 Feb 15, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Customizing functionality of SAP NetWeaver AS ABAP Platform (fixed in versions from 7.0 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.53, from 7.74 to 7.75) does not perform necessary authorization checks...Show more |
Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restricted. |
1Sap 3Advanced Business Application Programming Platform Kernel Advanced Business Application Programming Platform Krnl64nucAdvanced Business Application Programming Platform Krnl64ucNov 21, 2024 Feb 15, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 SAP NetWeaver AS ABAP Platform, Krnl64nuc 7.74, krnl64UC 7.73, 7.74, Kernel 7.73, 7.74, 7.75, fails to validate type of installation for an ABAP Server system correctly. That behavior may lead to situation, where busines...Show more |
SAP Disclosure Management (before version 10.1 Stack 1301) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
The Fiori Launchpad of SAP BusinessObjects, before versions 4.2 and 4.3, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwise be restricted. |
Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAP_GWFND 7.5, 7.51, 7.52, 7.53; SAP_BASIS 7.5) allows an attacker to access information which would otherwise be restricted. |
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity. |
1Sap 3Customer Relationship Management Webclient Ui S4fndSapscoreNov 21, 2024 Jan 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |