Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and...Show more |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls dir...Show more |
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privile...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspe...Show more |
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
|
1Sap 1Business Planning And Consolidation Jun 17, 2026 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the up...Show more |
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or cr...Show more |
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or cr...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Feb 14, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high im...Show more |
In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated att...Show more |
In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so o...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jan 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attac...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jan 10, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload cr...Show more |
1Sap 1Netweaver Application Server For Java Jun 17, 2026 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be us...Show more |
1Sap 1Business Planning And Consolidation Jun 17, 2026 Jan 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify,...Show more |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Jan 10, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that...Show more |
1Sap 4Netweaver Application Server Abap Netweaver Application Server Abap KernelNetweaver Application Server Abap Krnl64nuc+1 moreJun 17, 2026 Jan 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KR...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Jan 10, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulti...Show more |