Sap
sap
1,576 CVEs • 429 products
Products (429)
Click to collapseToggle
Products (429)
Click to collapse
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 2Abap Platform Netweaver Application Server AbapNov 21, 2024 Aug 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Improper access control in SOA Configuration Trace component in SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 702, 730, 731, 740, 750, allows any authenticated user to enumerate all SAP users, leading to Info...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Aug 12, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 SAP NetWeaver AS JAVA, versions - (ENGINEAPI 7.10; WSRM 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; J2EE-FRMW 7.10, 7.11), does not perform any authentication checks for a web service allowing the attacker to send several...Show more |
SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missin...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Aug 12, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end use...Show more |
1Sap 2Abap Platform Netweaver Application Server AbapNov 21, 2024 Aug 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 740, 750, 751, 752, 753, 754, 755, allows a business user to access the list of users in the given system using value help, leading to Information Disclosure. |
SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected Business Partner Generic Market Data (GMD) and change related GMD key figure values, due to Missing A...Show more |
Under certain conditions the upgrade of SAP Data Hub 2.7 to SAP Data Intelligence, version - 3.0, allows an attacker to access confidential system configuration information, that should otherwise be restricted, leading t...Show more |
1Sap 2Abap Platform Netweaver Application Server AbapNov 21, 2024 Aug 12, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection....Show more |
1Sap 1Adaptive Server Enterprise Nov 21, 2024 Aug 12, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compr...Show more |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Aug 12, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity. |
1Sap 1Netweaver Knowledge Management Nov 21, 2024 Aug 12, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limit...Show more |
1Sap 1Netweaver Knowledge Management Nov 21, 2024 Aug 12, 2020 N/A· v4 9.0 CRITICAL· v3 8.5 HIGH· v2 SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessin...Show more |
1Sap 1S/4 Hana Fiori Ui For General Ledger Accounting Nov 21, 2024 Aug 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachm...Show more |
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration. |
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration |
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID. |
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site. |
1Sap 1Netweaver Application Server Java Oct 31, 2025 Jul 14, 2020 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform...Show more |
1Sap 1Netweaver Application Server Java Nov 21, 2024 Jul 14, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method...Show more |
SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Inf...Show more |