Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 May 9, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would otherwise be restricted. Some users with...Show more |
1Sap 1Netweaver Application Server For Java Jun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object...Show more |
Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 May 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not suffici...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 May 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful e...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 May 9, 2023 N/A· v4 7.6 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high im...Show more |
1Sap 3Customer Relationship Management Webclient Ui S4fndSapscoreJun 17, 2026 May 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP CRM WebClient UI - versions SAPSCORE 129, S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficie...Show more |
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 May 9, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user int...Show more |
1Sap 2Customer Relationship Management S4fnd Customer Relationship Management Webclient UiJun 17, 2026 Apr 11, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This a...Show more |
A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very sam...Show more |
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker...Show more |
1Sap 1Netweaver As Abap Business Server Pages Jun 17, 2026 Apr 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain...Show more |
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classe...Show more |
1Sap 1Application Interface Framework Jun 17, 2026 Apr 11, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker...Show more |
1Sap 4Abap Platform Application Interface FrameworkBasis+1 moreJun 17, 2026 Apr 11, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of t...Show more |
1Sap 4Abap Platform Application Interface FrameworkBasis+1 moreJun 17, 2026 Apr 11, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can i...Show more |
1Sap 2Abap Platform Kernel Web DispatcherJun 17, 2026 Apr 11, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable access to backend applications from unwant...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Apr 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gai...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Apr 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can...Show more |