Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. Th...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to send an malicious request to the...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which wh...Show more |
1Sap 1Supplier Relationship Management Jun 17, 2026 May 13, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the v...Show more |
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. T...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 8, 2025 N/A· v4 7.1 HIGH· v3 N/A· v2 Due to insecure file permissions in SAP BusinessObjects Business Intelligence Platform, an attacker who has local access to the system could modify files potentially disrupting operations or cause service downtime hence...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Mar 11, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in...Show more |
SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive informatio...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Feb 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to imper...Show more |
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact...Show more |
SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jan 14, 2025 N/A· v4 9.1 CRITICAL· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker c...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jan 14, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The att...Show more |
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The...Show more |
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Dec 10, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information which would otherwise be restricted.This has low impact on Confidentiality with no impact on Integrity...Show more |
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of...Show more |
SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick the user into clicking...Show more |
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not prote...Show more |