Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system. |
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. |
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the dro...Show more |
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. |
1Sap 1Netweaver Master Data Management Server Jun 17, 2026 Feb 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'tr...Show more |
SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-digest signed SAML Assertion issued for an SAP HANA instance might be able to tamper with it and alter...Show more |
1Sap 1Software Provisioning Manager Jun 17, 2026 Feb 9, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Software Provisioning Manager 1.0 (SAP NetWeaver Master Data Management Server 7.1) does not have an option to set password during its installation, this allows an authenticated attacker to perform various security a...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Feb 9, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nulli...Show more |
In CLA-Assistant, versions before 2.8.5, due to improper access control an authenticated user could access API endpoints which are not intended to be used by the user. This could impact the integrity of the application. |
1Sap 1Enterprise Performance Management Jun 17, 2026 Jan 12, 2021 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 SAP EPM Add-in for Microsoft Office, version - 1010 and SAP EPM Add-in for SAP Analysis Office, version - 2.8, allows an authenticated attacker with user privileges to parse malicious XML files which could result in XXE-...Show more |
1Sap 1Netweaver Master Data Management Jun 17, 2026 Jan 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When security guidelines for SAP NetWeaver Master Data Management running on windows have not been thoroughly reviewed, it might be possible for an external operator to try and set custom paths in the MDS server configur...Show more |
The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table. |
SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business...Show more |
1Sap 2Business Warehouse Bw/4hanaJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Vi...Show more |
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the backend database. An attacker can include their own SQL commands which the database will execute with...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jan 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated BMP file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |