Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbit...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Dec 12, 2023 N/A· v4 9.4 CRITICAL· v3 N/A· v2 SAP GUI for Windows and SAP GUI for Java allow an unauthenticated attacker to access information which would otherwise be restricted and confidential. In addition, this vulnerability allows the unauthenticated attacker t...Show more |
SAP GUI for Windows and SAP GUI for Java - versions SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, allow an unauthenticated attacker to access information which would otherwise be restricted and confidential...Show more |
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform Denial of service attack from adjacent UI by sending a malicious request which leads to low impact on the availability and no...Show more |
The SAP HCM (SMART PAYE solution) - versions S4HCMCIE 100, SAP_HRCIE 600, SAP_HRCIE 604, SAP_HRCIE 608, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After su...Show more |
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed throu...Show more |
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re...Show more |
An unauthenticated attacker can embed a hidden access to a Biller Direct URL in a frame which, when loaded by the user, will submit a cross-site scripting request to the Biller Direct system. This can result in the discl...Show more |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Dec 12, 2023 N/A· v4 7.6 HIGH· v3 N/A· v2 SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity o...Show more |
1Sap 1Businessobjects Web Intelligence Jun 17, 2026 Dec 12, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable pag...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Nov 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KERNEL 7.93, KERNEL 7.94, KERNEL64UC 7.22, K...Show more |
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additional...Show more |
1Sap 4Enable Now Enable Now Consump Del Enable Now Wpb ManagerEnable Now Wpb Manager Ce+1 moreJun 17, 2026 Oct 30, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt c...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Oct 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the applicatio...Show more |
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality. |
1Sap 1Businessobjects Web Intelligence Jun 17, 2026 Oct 10, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve th...Show more |
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has low impact on the confidentiality and integ...Show more |
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful expl...Show more |
SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file, although not used, would be accessed dur...Show more |