Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Sep 13, 2022 N/A· v4 5.2 MEDIUM· v3 N/A· v2 Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retrieve (non-personal) system data, modify system data but can't make the system unavailable. This needs t...Show more |
SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall....Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Sep 13, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session informati...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Sep 13, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 430, allows an attacker to access certain unencrypted sensitive parameters which would otherwise be r...Show more |
SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script...Show more |
In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves. |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Sep 13, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Script...Show more |
In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within quotes, leading to a vulnerability known as Unquoted Service Path which allows a user to gain SYSTE...Show more |
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confi...Show more |
Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted. |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 10, 2022 N/A· v4 8.2 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the at...Show more |
Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jul 12, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful expl...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,...Show more |
SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-perman...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jul 12, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jul 12, 2022 N/A· v4 6.0 MEDIUM· v3 6.5 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modi...Show more |