Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 3Content Server Netweaver Application Server AbapWeb DispatcherJun 17, 2026 Feb 9, 2022 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticat...Show more |
1Sap 1Erp Human Capital Management Jun 17, 2026 Feb 9, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll inf...Show more |
Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an attacker could submit multiple HTTP serve...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request whic...Show more |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 Feb 9, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Wi...Show more |
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script...Show more |
The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous con...Show more |
1Sap 1Enterprise Threat Detection Jun 17, 2026 Jan 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD are using SAP UI5 sta...Show more |
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. |
1Sap 2Netweaver Abap Netweaver Application Server AbapJun 17, 2026 Jan 14, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Dec 14, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to...Show more |
SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which could lead to escalation of privileges. |
SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem st...Show more |
1Sap 2Abap Platform Netweaver Application Server AbapJun 17, 2026 Dec 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Dec 14, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens manipulated Jupiter Tessellation (.jt) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user unti...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Dec 14, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens manipulated Tagged Image File Format (.tif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Dec 14, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens a manipulated GIF (.gif) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of t...Show more |
SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypted. For an attacker to discover vulnerable function in-depth application knowledg...Show more |
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted da...Show more |