Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until resta...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user unti...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated Encapsulated Post Script (.eps, ai.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user unti...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the us...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until r...Show more |
1Sap 1Adaptive Server Enterprise Feb 25, 2026 Jun 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
1Sap 1Adaptive Server Enterprise Nov 21, 2024 Jun 14, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system. |
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk ro...Show more |
1Sap 3Erp Financial Accounting Erp Localization For Cee CountriesS/4hanaNov 21, 2024 Jun 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to user...Show more |
1Sap 1Netweaver Development Infrastructure Nov 21, 2024 Jun 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code...Show more |
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vul...Show more |
1Sap 2Host Agent Netweaver AbapNov 21, 2024 Jun 14, 2022 N/A· v4 5.0 MEDIUM· v3 4.6 MEDIUM· v2 SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49,...Show more |
1Sap 2Host Agent Netweaver AbapNov 21, 2024 Jun 14, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, al...Show more |
1Sap 4Netweaver As Abap Netweaver As Abap Krnl64nucNetweaver As Abap Krnl64uc+1 moreNov 21, 2024 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions...Show more |
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibi...Show more |
1Sap 1Contributor License Agreement Assistant Nov 21, 2024 Jun 6, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application. |
1Sap 1Business Objects Business Intelligence Platform Nov 21, 2024 Jun 6, 2022 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possi...Show more |