Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the...Show more |
1Sap 2Netweaver Abap Netweaver As AbapNov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, KRNL64UC 8.04, 7.22, 7.22EXT, 7.49, 7.53, KRNL64NUC 7.22, 7.22EXT, 7.4...Show more |
S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for Customer, Supplier and Business Partner objects exposes the private ad...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute crafted database queries, that could expose the backend database. Success...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Feb 9, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user un...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Feb 9, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Feb 9, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to t...Show more |
1Sap 3Content Server Netweaver Application Server AbapWeb DispatcherFeb 25, 2026 Feb 9, 2022 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticat...Show more |
1Sap 1Erp Human Capital Management Nov 21, 2024 Feb 9, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll inf...Show more |
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP serve...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request whic...Show more |
1Sap 1Adaptive Server Enterprise Feb 24, 2026 Feb 9, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Wi...Show more |
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script...Show more |
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous con...Show more |
1Sap 1Enterprise Threat Detection Feb 24, 2026 Jan 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD are using SAP UI5 sta...Show more |
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. |
1Sap 2Netweaver Abap Netweaver Application Server AbapNov 21, 2024 Jan 14, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Dec 14, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to...Show more |
SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which could lead to escalation of privileges. |