← Back

Sap

sap

1,576 CVEs • 429 products

Products (429)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Hybris
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side imple...Show more
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC.Show less
1Sap
1Netweaver
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.
1Sap
1People Profile
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges.
1Sap
1Business One
Nov 21, 2024
Sep 11, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.
1Sap
1Mobile Platform
Nov 21, 2024
Sep 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occasionally receive some data values of a different user.
1Sap
1Business One
Nov 21, 2024
Sep 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which would otherwise be restricted.
1Sap
1Adaptive Server Enterprise
Nov 21, 2024
Sep 11, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access information which would otherwise be restricted.
1Sap
1Enterprise Financial Services
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary authorization checks for an authenticated user, resulting in escalation...Show more
SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.Show less
1Sap
1Enterprise Financial Services
Nov 21, 2024
Sep 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of...Show more
SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.Show less
1Sap
1Netweaver Application Server Java
Nov 21, 2024
Sep 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability.
1Sap
1Hana Extended Application Services
Nov 21, 2024
Aug 14, 2018
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could a...Show more
XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could access controller resources via active CLI session even after corresponding authorizations have been revoked meanwhile by an administrator user. Similarly, an attacker who managed to gain access to the platform user's session might misuse the session token even after the session has been closed.Show less
1Sap
1Maxdb
Nov 21, 2024
Aug 14, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive data from database.
1Sap
1Supplier Relationship Management Mdm Catalog
Nov 21, 2024
Aug 14, 2018
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on w...Show more
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.Show less
1Sap
1Supplier Relationship Management Mdm Catalog
Nov 21, 2024
Aug 14, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.
1Sap
1Businessobjects Business Intelligence
Nov 21, 2024
Aug 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database.
1Sap
1Businessobjects Business Intelligence
Nov 21, 2024
Aug 14, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure.
1Sap
1Businessobjects Business Intelligence
Nov 21, 2024
Aug 14, 2018
N/A· v4
9.6 CRITICAL· v3
5.5 MEDIUM· v2
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Re...Show more
AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Request Forgery (SSRF) vulnerability.Show less
1Sap
1Businessobjects Financial Consolidation
Nov 21, 2024
Aug 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1Sap
2Businessobjects Business Intelligence
Internet Graphics Server
Nov 21, 2024
Aug 14, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML pag...Show more
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.Show less
1Sap
1Sap Kernel
Nov 21, 2024
Aug 14, 2018
N/A· v4
5.5 MEDIUM· v3
5.5 MEDIUM· v2
Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49,...Show more
Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49, 7.53 and 7.73, allows an attacker to transport information which would otherwise be restricted.Show less