Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful expl...Show more |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,...Show more |
SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-perman...Show more |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jul 12, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of...Show more |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Jul 12, 2022 N/A· v4 6.0 MEDIUM· v3 6.5 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR file's password under certain conditions, enabling the attacker to modi...Show more |
Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the system temporarily inoperative. |
Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive information (e.g., high privileged account credent...Show more |
Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an...Show more |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interact...Show more |
1Sap 1Business Objects Business Intelligence Platform Nov 21, 2024 Jul 12, 2022 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authenticated attacker who has access to BI admin console to send crafted queries and extract data from th...Show more |
1Sap 1Business Objects Business Intelligence Platform Nov 21, 2024 Jul 12, 2022 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or m...Show more |
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenti...Show more |
SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
1Sap 1Enterprise Extension Defense Forces & Public Security Nov 21, 2024 Jul 12, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The application SAP Enterprise Extension Defense Forces & Public Security - versions 605, 606, 616,617,618, 802, 803, 804, 805, 806, does not perform necessary authorization checks for an authenticated user over the netw...Show more |
1Sap 1Businessobjects Bw Publisher Service Nov 21, 2024 Jul 12, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affecte...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify rights of objects it doesn't own and which would otherwise be restricte...Show more |
1Sap 1Business One License Service Api Feb 25, 2026 Jul 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can br...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated Scalable Vector Graphics (.svg, svg.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user unt...Show more |