← Back

Sap

sap

1,589 CVEs • 430 products

Products (430)

Click to collapse
Toggle
Netweaver
netweaver
Hana
hana
Business One
business_one
Sap Basis
sap_basis
S/4hana
s/4hana
Host Agent
host_agent
Enable Now
enable_now
S4core
s4core
Approuter
approuter
Sap Db
sap_db
Abap Platform
abap_platform
Sap Kernel
sap_kernel
Commerce
commerce
Rfc Library
rfc_library
Maxdb
maxdb
Sql Anywhere
sql_anywhere
Trex
trex
Hybris
hybris
Hana Database
hana_database
Afaria
afaria
Sapscore
sapscore
S/4 Hana
s/4_hana
Sapgui
sapgui
Erp
erp
Basis
basis
Fiori Client
fiori_client
Sap R 3
sap_r_3
S4fnd
s4fnd
Bw/4hana
bw/4hana
Powerdesigner
powerdesigner
Enjoysap
enjoysap
Saplpd
saplpd
J2ee Engine
j2ee_engine
Ui
ui
Fiori
fiori
Focused Run
focused_run
Sapsprint
sapsprint

CVEs (1,589)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Business One
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.
1Sap
1Cloud Platform
Nov 21, 2024
Apr 10, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top...Show more
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.Show less
1Sap
1Businessobjects
Nov 21, 2024
Apr 10, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password...Show more
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password change for a user, all other active sessions created using older password continues to be active.Show less
1Sap
1Crystal Reports Server
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.
1Sap
1Solution Manager
Nov 21, 2024
Apr 10, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
1Sap
1Disclosure Management
Nov 21, 2024
Apr 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
1Sap
1Disclosure Management
Nov 21, 2024
Apr 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a spe...Show more
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.Show less
1Sap
1Hana
Nov 21, 2024
Mar 14, 2018
N/A· v4
8.4 HIGH· v3
3.5 LOW· v2
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver...Show more
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.Show less
1Sap
1Process Monitoring Infrastructure
Nov 21, 2024
Mar 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs.
1Sap
1Business Client
May 27, 2025
Mar 14, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.
1Sap
1Businessobjects Business Intelligence Platform
Nov 21, 2024
Mar 14, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.
1Sap
1Customer Relationship Management
Oct 31, 2025
Mar 1, 2018
N/A· v4
6.6 MEDIUM· v3
6.5 MEDIUM· v2
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to t...Show more
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.Show less
1Sap
1Netweaver System Landscape Directory
Nov 21, 2024
Mar 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
1Sap
1Business Application Software Integrated Solution
Nov 21, 2024
Mar 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters r...Show more
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.Show less
1Sap
1Netweaver Portal
Nov 21, 2024
Mar 1, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1Sap
1Internet Graphics Server
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service.
1Sap
1Internet Graphics Server
Nov 21, 2024
Feb 14, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.
1Sap
1Internet Graphics Server
Nov 21, 2024
Feb 14, 2018
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.
1Sap
1Internet Graphics Server
Nov 21, 2024
Feb 14, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
1Sap
1Internet Graphics Server
Nov 21, 2024
Feb 14, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.