Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 2Netweaver Application Server Abap S/4 HanaJun 17, 2026 Dec 9, 2020 N/A· v4 7.6 HIGH· v3 7.5 HIGH· v2 SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA (SAP Landscape Transformation), versions - 101, 102, 103, 10...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Dec 9, 2020 N/A· v4 9.6 CRITICAL· v3 5.5 MEDIUM· v2 SAP BusinessObjects BI Platform (Crystal Report), versions - 4.1, 4.2, 4.3, does not sufficiently validate uploaded XML entities during crystal report generation due to missing XML validation, An attacker with basic priv...Show more |
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks for an authenticated user. Due to inadequate access control, a network attacker authenticated as a reg...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Dec 9, 2020 N/A· v4 10.0 CRITICAL· v3 9.0 HIGH· v2 SAP NetWeaver AS JAVA (P2P Cluster Communication), versions - 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows arbitrary connections from processes because of missing authentication check, that are outside the cluster and even...Show more |
SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to enter formulas which can call external appl...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Dec 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format validation, leading to Unrestricted File Upl...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Dec 9, 2020 N/A· v4 4.5 MEDIUM· v3 2.7 LOW· v2 SAP AS JAVA (Key Storage Service), versions - 7.10, 7.11, 7.20 ,7.30, 7.31, 7.40, 7.50, has the key material which is stored in the SAP NetWeaver AS Java Key Storage service stored in the database in the DER encoded form...Show more |
In certain situations, an attacker with regular user credentials and local access to an ASE cockpit installation can access sensitive information which appears in the installation log files. This information although sen...Show more |
1Sap 1Fiori Launchpad (news Tile Application) Jun 17, 2026 Nov 13, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim),...Show more |
SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check. |
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integr...Show more |
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impa...Show more |
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to...Show more |
SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 10, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Nov 10, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of I...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Nov 10, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Nov 10, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user...Show more |
1Sap 1Fiori Launchpad (news Tile Application) Jun 17, 2026 Nov 10, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems be...Show more |
1Sap 1Process Integration (pgp Module Business To Business Add On) Jun 17, 2026 Nov 10, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be use...Show more |