Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 22, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restar...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 22, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the a...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 22, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until res...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 10, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vuln...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated Universal 3D (.U3D) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the app...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated Portable Document Format (.PDF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated Tag Image File Format (.TIFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the us...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated HPGL format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the a...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated Jupiter Tessellation (.JT) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated Interchange File Format (.IFF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the u...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When a user opens manipulated Computer Graphics Metafile (.CGM) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to th...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens manipulated PhotoShop Document (.PSD) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user u...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Mar 9, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 When a user opens manipulated Graphics Interchange Format (.GIF) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to t...Show more |
1Sap 1Netweaver Knowledge Management Jun 17, 2026 Mar 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers...Show more |
SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
1Sap 1Enterprise Financial Services Jun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authorization checks for an authenticated user, resulting in escalation of priv...Show more |
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind. |
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects,...Show more |
1Sap 1Manufacturing Integration And Intelligence Jun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forw...Show more |