Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jun 14, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated AutoCAD (.dwg, TeighaTranslator.exe) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until r...Show more |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 Jun 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 Jun 14, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system. |
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk ro...Show more |
1Sap 3Erp Financial Accounting Erp Localization For Cee CountriesS/4hanaJun 17, 2026 Jun 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to user...Show more |
1Sap 1Netweaver Development Infrastructure Jun 17, 2026 Jun 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code...Show more |
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vul...Show more |
1Sap 2Host Agent Netweaver AbapJun 17, 2026 Jun 14, 2022 N/A· v4 5.0 MEDIUM· v3 4.6 MEDIUM· v2 SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49,...Show more |
1Sap 2Host Agent Netweaver AbapJun 17, 2026 Jun 14, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, al...Show more |
1Sap 4Netweaver As Abap Netweaver As Abap Krnl64nucNetweaver As Abap Krnl64uc+1 moreJun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP Platform - versions...Show more |
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibi...Show more |
1Sap 1Contributor License Agreement Assistant Jun 17, 2026 Jun 6, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application. |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Jun 6, 2022 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possi...Show more |
1Sap 3Netweaver As Abap Kernel Netweaver As Abap Krnl64nucNetweaver As Abap Krnl64ucJun 17, 2026 May 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption. |
Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 May 11, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 May 11, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack. |
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted. |
1Sap 2Businessobjects Businessobjects Business IntelligenceJun 17, 2026 May 11, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high i...Show more |
1Sap 3Netweaver As Abap Kernel Netweaver As Abap Krnl64ucWebdispatcherJun 17, 2026 May 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |