Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 2Business Warehouse Business Warehouse Virtual CompJun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, a...Show more |
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the func...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP CRM WebClient does not
perform necessary authorization check for an authenticated user, resulting in
escalation of privileges. This could allow an attacker to access some sensitive
information. |
SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and a...Show more |
1Sap 2Saptmui Transportation ManagementJun 17, 2026 Jul 9, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a...Show more |
Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which might be downloaded and executed by the user which cou...Show more |
WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 7.7 HIGH· v3 N/A· v2 SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in informat...Show more |
SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities...Show more |
Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confi...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on co...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in t...Show more |
1Sap 1Netweaver Knowledge Management And Collaboration (kmc Cm) Jun 17, 2026 Jul 9, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to weak encoding of user-controlled input in SAP NetWeaver Knowledge Management XMLEditor which allows malicious scripts can be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnera...Show more |
SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of p...Show more |
Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no i...Show more |
1Sap 1Student Life Cycle Management Jun 17, 2026 Jun 11, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading to the potential escalation of privileges. On successful exploitation it could allow an attacker to a...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jun 11, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no...Show more |
1Sap 1Customer Relationship Management Webclient Ui Jun 17, 2026 Jun 11, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the vic...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jun 11, 2024 N/A· v4 6.0 MEDIUM· v3 N/A· v2 On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker...Show more |
An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to access, modify, or make the related information unavailable in the victi...Show more |