Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side imple...Show more |
In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source. |
Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges. |
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack. |
Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occasionally receive some data values of a different user. |
Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which would otherwise be restricted. |
1Sap 1Adaptive Server Enterprise Nov 21, 2024 Sep 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access information which would otherwise be restricted. |
1Sap 1Enterprise Financial Services Nov 21, 2024 Sep 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary authorization checks for an authenticated user, resulting in escalation...Show more |
1Sap 1Enterprise Financial Services Nov 21, 2024 Sep 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Sep 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability. |
1Sap 1Hana Extended Application Services Nov 21, 2024 Aug 14, 2018 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS), version 1, advanced server may have an unintentional prolonged period of validity. Consequently, a platform user could a...Show more |
SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive data from database. |
1Sap 1Supplier Relationship Management Mdm Catalog Nov 21, 2024 Aug 14, 2018 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on w...Show more |
1Sap 1Supplier Relationship Management Mdm Catalog Nov 21, 2024 Aug 14, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted. |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Aug 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP BusinessObjects Business Intelligence (Launchpad Web Intelligence), version 4.2, allows an attacker to execute crafted InfoObject queries, exposing the CMS InfoObjects database. |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Aug 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Admin tools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allow an unauthenticated user to read sensitive information (server name), hence leading to an information disclosure. |
1Sap 1Businessobjects Business Intelligence Nov 21, 2024 Aug 14, 2018 N/A· v4 9.6 CRITICAL· v3 5.5 MEDIUM· v2 AdminTools in SAP BusinessObjects Business Intelligence, versions 4.1, 4.2, allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application, resulting in a Server-Side Re...Show more |
1Sap 1Businessobjects Financial Consolidation Nov 21, 2024 Aug 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP BusinessObjects Financial Consolidation, versions 10.0, 10.1, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 2Businessobjects Business Intelligence Internet Graphics ServerNov 21, 2024 Aug 14, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML pag...Show more |
Under certain conditions the SAP Change and Transport System (ABAP), SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49,...Show more |