← Back

Sap

sap

1,576 CVEs • 429 products

Products (429)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
3Ea Finserv
S4coreSapscore
Nov 21, 2024
May 9, 2018
N/A· v4
4.6 MEDIUM· v3
5.5 MEDIUM· v2
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escal...Show more
SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.Show less
1Sap
1Maxdb Odbc Driver
Nov 21, 2024
May 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
1Sap
1Identity Management
Nov 21, 2024
May 9, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be restricted.
1Sap
1Identity Management
Nov 21, 2024
May 9, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
1Sap
2J2ee Engine Server Core
Netweaver Java Web Container And Http Service Engine
Nov 21, 2024
May 9, 2018
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlle...Show more
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.Show less
1Sap
1Disclosure Management
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
1Sap
1Disclosure Management
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
1Sap
1Business One
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
1Sap
1Cloud Platform
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top...Show more
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.Show less
1Sap
1Businessobjects
Nov 21, 2024
Apr 10, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password...Show more
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.Show less
1Sap
1Crystal Reports Server
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.
1Sap
1Solution Manager
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
1Sap
1Disclosure Management
Nov 21, 2024
Apr 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
1Sap
1Disclosure Management
Nov 21, 2024
Apr 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a spe...Show more
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.Show less
1Sap
1Hana
Nov 21, 2024
Mar 14, 2018
N/A· v4
8.4 HIGH· v3
3.5 LOW· v2
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver...Show more
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.Show less
1Sap
1Process Monitoring Infrastructure
Nov 21, 2024
Mar 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs.
1Sap
1Business Client
May 27, 2025
Mar 14, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.
1Sap
1Businessobjects Business Intelligence Platform
Nov 21, 2024
Mar 14, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
1Sap
1Customer Relationship Management
Oct 31, 2025
Mar 1, 2018
N/A· v4
6.6 MEDIUM· v3
6.5 MEDIUM· v2
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to t...Show more
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.Show less
1Sap
1Netweaver System Landscape Directory
Nov 21, 2024
Mar 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.