Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically. |
By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT,...Show more |
Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker ca...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the netwo...Show more |
SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 12, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does not sufficiently validate the XML document accepted from an untrusted source, which might result in a...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF token visible in the URL may possibly lead to information disclosure vulnerability. |
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use indirect identifiers. |
1Sap 1Netweaver Application Server For Java Jun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges. |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Inform...Show more |
A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by exploiting insufficient validation of path information in SAP Focused Run (Simple Diagnostics Agent 1.0)...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user unt...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable t...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user un...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Apr 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interact...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see through relational or OLAP connections. The main impact is the disclosure of com...Show more |
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks. |