Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-...Show more |
SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error....Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Mar 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In SAP BusinessObjects Business Intelligence Platform (Web Services) - versions 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own admintools, leading to a high...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 9.6 CRITICAL· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a director...Show more |
1Sap 1Netweaver Application Server For Java Nov 21, 2024 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and dir...Show more |
SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to...Show more |
1Sap 1Netweaver Application Server For Java Nov 21, 2024 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity
|
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can cr...Show more |
SAP Content Server - version 7.53, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can read and modify some sensitive...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Mar 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an...Show more |
1Sap 1Business Objects Business Intelligence Platform Nov 21, 2024 Mar 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI...Show more |
1Sap 1Business Objects Business Intelligence Platform Nov 21, 2024 Mar 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources...Show more |
Due to insufficient input sanitization, SAP ABAP - versions 751, 753, 753, 754, 756, 757, 791, allows an authenticated high privileged user to alter the current session of the user by injecting the malicious database que...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure h...Show more |
1Sap 1Netweaver Application Server For Java Nov 21, 2024 Mar 14, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which c...Show more |
Due to insufficient encoding of user input, SAP NetWeaver - versions 700, 701, 702, 731, 740, 750, allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password, which could l...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application o...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Feb 14, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitati...Show more |
1Sap 1Netweaver As Abap Business Server Pages Nov 21, 2024 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leverag...Show more |