Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application. This could make the app...Show more |
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions result...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Sep 12, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can b...Show more |
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploita...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Sep 12, 2023 N/A· v4 9.9 CRITICAL· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On succ...Show more |
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user....Show more |
1Sap 9Commoncryptolib Content ServerExtended Application Services And Runtime+6 moreJun 17, 2026 Sep 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the applicati...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Sep 12, 2023 N/A· v4 7.3 HIGH· v3 N/A· v2 Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over...Show more |
The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When clicked on the XML file in the attachment sect...Show more |
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData call.
|
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploi...Show more |
1Sap 9Commoncryptolib Content ServerExtended Application Services And Runtime+6 moreJun 17, 2026 Sep 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it u...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Sep 12, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snippet through the UI, which leads to low imp...Show more |
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiali...Show more |
1Sap 1Contributor License Agreement Assistant Jun 17, 2026 Aug 15, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to r...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 8, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly, due to which attacker might be able to ge...Show more |
1Sap 2Commerce Cloud Commerce HycomJun 17, 2026 Aug 8, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase. |
SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to Cross-site scripting. This could lead to...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 Aug 8, 2023 N/A· v4 5.8 MEDIUM· v3 N/A· v2 SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master Data for Business Partners replication f...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP...Show more |