Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Nov 10, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Nov 10, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of I...Show more |
1Sap 1Netweaver Application Server Abap Nov 21, 2024 Nov 10, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Nov 10, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user...Show more |
1Sap 1Fiori Launchpad (news Tile Application) Nov 21, 2024 Nov 10, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems be...Show more |
1Sap 1Process Integration (pgp Module Business To Business Add On) Nov 21, 2024 Nov 10, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be use...Show more |
1Sap 1Commerce Cloud (accelerator Payment Mock) Nov 21, 2024 Nov 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be proces...Show more |
1Sap 1Commerce Cloud (accelerator Payment Mock) Nov 21, 2024 Nov 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be proces...Show more |
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could con...Show more |
1Sap 2Sap As Abap(dmis) Sap S4 Hana(dmis)Nov 21, 2024 Nov 10, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject...Show more |
SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder. |
1Sap 1Netweaver Design Time Repository Nov 21, 2024 Oct 20, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 2Focused Run Solution ManagerNov 21, 2024 Oct 20, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest hav...Show more |
1Sap 1Netweaver Composite Application Framework Nov 21, 2024 Oct 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user...Show more |
1Sap 1Netweaver Compare Systems Nov 21, 2024 Oct 20, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS leve...Show more |
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to...Show more |
1Sap 13d Visual Enterprise Viewer Nov 21, 2024 Oct 20, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive information when the victim loads the malicious file into the VE viewe...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Oct 20, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Oct 15, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation...Show more |