Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 4Landscape Transformation Landscape Transformation Replication ServerS/4hana+1 moreNov 21, 2024 Sep 14, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Due to improper input sanitization, an authenticated user with certain specific privileges can remotely call NZDT function modules listed in Solution Section to execute manipulated query or inject ABAP code to gain acces...Show more |
1Sap 1Analysis For Microsoft Office Nov 21, 2024 Sep 14, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 SAP Analysis for Microsoft Office - version 2.8, allows an attacker with high privileges to read sensitive data over the network, and gather or change information in the current system without user interaction. The attac...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Sep 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When a user opens manipulated files received from untrusted sources in SAP 3D Visual Enterprise Viewer version - 9, the application crashes and becomes temporarily unavailable to the user until restart of the application...Show more |
1Sap 1Erp Financial Accounting Nov 21, 2024 Sep 14, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attack...Show more |
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing,...Show more |
SAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22, 7.49, 7.53, 7.77, 7.81, 7.83 processes allow an unauthenticated attacker to submi...Show more |
When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Sep 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges. |
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privi...Show more |
1Sap 1Netweaver Knowledge Management Xml Forms Nov 21, 2024 Sep 14, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerability which allows a non-administrative authenticated attacker to craft a malicious XSL stylesheet file...Show more |
SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained. |
Under certain conditions, SAP Business One version - 10.0, allows an unauthorized attacker to get access to some encrypted sensitive information, but does not have control over kind or degree. |
SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high leve...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Sep 14, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits...Show more |
Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability through phishing an...Show more |
Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability when creating a new...Show more |
Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability wh...Show more |
Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets e...Show more |
1Sap 1Netweaver Enterprise Portal Nov 21, 2024 Sep 14, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attac...Show more |
1Sap 1Netweaver Knowledge Management Nov 21, 2024 Aug 10, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's con...Show more |