Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an u...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Jun 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver AS for ABAP (Web Survey), versions - 700, 702, 710, 711, 730, 731, 750, 750, 752, 75A, 75F, does not sufficiently encode input and output parameters which results in reflected cross site scripting vulnerabi...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Jun 9, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticate...Show more |
Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application. |
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 May 11, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not check the file type extension of the file uploaded from local source. An attacker could craft a m...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 May 11, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate an XML document uploaded from local source. An attacker can craft a malicio...Show more |
1Sap 2Business One Hana Chef Cookbook Business OneNov 21, 2024 May 11, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and...Show more |
1Sap 2Business One Hana Chef Cookbook Business OneNov 21, 2024 May 11, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could t...Show more |
1Sap 1Chef Business One Cookbook Nov 21, 2024 May 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to...Show more |
In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the v...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 May 11, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could th...Show more |
An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered. This could further lead to complete comprom...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Repository JAVA Mappings), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, SAP...Show more |
1Sap 1Netweaver Process Integration Nov 21, 2024 Apr 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Integration Builder Framework), versions - 7.10, 7.30, 7.31, 7.40, 7.50, allows an attacker to access information under certain conditions, which would o...Show more |
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP EarlyWatch Alert servi...Show more |
1Sap 1Fiori Apps 2.0 For Travel Management In Sap Erp Nov 21, 2024 Apr 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation o...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Apr 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An RFC enabled function module SPI_WAIT_MILLIS in SAP NetWeaver AS ABAP, versions - 731, 740, 750, allows to keep a work process busy for any length of time. An attacker could call this function module multiple times to...Show more |
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the applic...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Apr 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (...Show more |