Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 1Commerce Cloud (accelerator Payment Mock) Jun 17, 2026 Nov 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be proces...Show more |
1Sap 1Commerce Cloud (accelerator Payment Mock) Jun 17, 2026 Nov 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be proces...Show more |
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could con...Show more |
1Sap 2Sap As Abap(dmis) Sap S4 Hana(dmis)Jun 17, 2026 Nov 10, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject...Show more |
SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder. |
1Sap 1Netweaver Design Time Repository Jun 17, 2026 Oct 20, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Design Time Repository (DTR), versions - 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 2Focused Run Solution ManagerJun 17, 2026 Oct 20, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an unauthenticated attackers to bypass the authentication if the default passwords for Admin and Guest hav...Show more |
1Sap 1Netweaver Composite Application Framework Jun 17, 2026 Oct 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a reflected cross site scripting vulnerability in SAP NetWeaver Composite Application Framework, versions - 7.20, 7.30, 7.31, 7.40, 7.50. An unauthenticated attacker can trick an unsuspecting authenticated user...Show more |
1Sap 1Netweaver Compare Systems Jun 17, 2026 Oct 20, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 SAP NetWeaver (Compare Systems) versions - 7.20, 7.30, 7.40, 7.50, does not sufficiently validate uploaded XML documents. An attacker with administrative privileges can retrieve arbitrary files including files on OS leve...Show more |
SAP Banking Services version 500, use an incorrect authorization object in some of its reports. Although the affected reports are protected with otherauthorization objects, exploitation of the vulnerability could lead to...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Oct 20, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version 9, allows an attacker to send certain manipulated file to the victim, which can lead to leakage of sensitive information when the victim loads the malicious file into the VE viewe...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Oct 20, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary values as CMS parameters to perform lookups on the internal network which...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Oct 15, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Oct 15, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Hemisphere Binary (.rh) file received from untrusted sources which results in crashing of the application and becoming temporarily una...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Oct 15, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Right Computer Graphics Metafile (.cgm) file received from untrusted sources which results in crashing of the application and becoming tempo...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Oct 15, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated Jupiter Tessallation(.jt) file received from untrusted sources which results in crashing of the application and becoming temporarily unavail...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Oct 15, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |
1Sap 13d Visual Enterprise Viewer Jun 17, 2026 Oct 15, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PDF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user re...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Oct 15, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 User enumeration vulnerability can be exploited to get a list of user accounts and personal user information can be exposed in SAP NetWeaver Application Server ABAP (POWL test application) versions - 710, 711, 730, 731,...Show more |
1Sap 1Business Planning And Consolidation Jun 17, 2026 Oct 15, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application content without authorization, and to potential...Show more |