Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to access information which would otherwise be restricted. |
1Sap 1Treasury And Risk Management Jun 17, 2026 May 14, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_D...Show more |
The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information including credentials which can be misused by the attacker. |
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML E...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Apr 10, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerable to Digital Signature Spoofing. It is possible to spoof XML signatures and send arbitrary requests...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Apr 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like relea...Show more |
1Sap 1Business Application Software Integrated Solution Jun 17, 2026 Apr 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BASIS (fixed in versions 7.0 to 7.02, 7.10 to 7.30, 7.31, 7.40, 7.50 to 7.53) do not perform necessary...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Apr 10, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker to see the names of database t...Show more |
1Sap 1Hana Extended Application Services Jun 17, 2026 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). |
1Sap 2Banking Services From Sap S/4hana Financial Products SubledgerJun 17, 2026 Mar 12, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) performs an inadequate authorization check for an authenticated user, potentially resulting in escalation...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40 and 7.50, does not sufficiently encode user-controlled inputs, which results in cross-site...Show more |
SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service (i.e. denial of service). Fixed in versions 3.1 SP03 PL02, SDK 3.1 SP04, or late...Show more |
1Sap 3Advanced Business Application Programming Platform Advanced Business Application Programming ServerSap KernelJun 17, 2026 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted from an untrusted source, leading to an XML External Entity (XEE) vulnerability. Fixed in Kernel 7.2...Show more |
1Sap 5Advanced Business Application Programming Platform Kernel Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 moreJun 17, 2026 Mar 12, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corrected in the following versions: KRNL32NUC...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Mar 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Mar 12, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently validate an XML document accepted from an untrusted source. |
1Sap 1Manufacturing Integration And Intelligence Jun 17, 2026 Feb 15, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens. This might lead to XSRF attacks in case the data is being posted to the Ser...Show more |
1Sap 1Hana Extended Application Services Jun 17, 2026 Feb 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Under certain conditions SAP HANA Extended Application Services, version 1.0, advanced model (XS advanced) writes credentials of platform users to a trace file of the SAP HANA system. Even though this trace file is prote...Show more |
1Sap 5Advanced Business Application Programming Platform Kernel Advanced Business Application Programming Platform Krnl32nucAdvanced Business Application Programming Platform Krnl32uc+2 moreJun 17, 2026 Feb 15, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 SLD Registration of ABAP Platform allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Fixed in versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT,KRNL32UC 7.2...Show more |
1Sap 1Businessobjects Bi Platform Jun 17, 2026 Feb 15, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP WebIntelligence BILaunchPad, versions 4.10, 4.20, does not sufficiently encode user-controlled inputs in generated HTML reports, resulting in Cross-Site Scripting (XSS) vulnerability. |