Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sap 2Abap Platform Netweaver Application Server AbapJun 17, 2026 Aug 12, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection....Show more |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 Aug 12, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable installation log files leading to a compr...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Aug 12, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity. |
1Sap 1Netweaver Knowledge Management Jun 17, 2026 Aug 12, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to upload a malicious file and also to access, modify or make unavailable existing files but the impact is limit...Show more |
1Sap 1Netweaver Knowledge Management Jun 17, 2026 Aug 12, 2020 N/A· v4 9.0 CRITICAL· v3 8.5 HIGH· v2 SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessin...Show more |
1Sap 1S/4 Hana Fiori Ui For General Ledger Accounting Jun 17, 2026 Aug 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachm...Show more |
Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration. |
SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration |
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID. |
SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site. |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2020 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to exploit a method...Show more |
SAP NetWeaver - XML Toolkit for JAVA (ENGINEAPI) (versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50), under certain conditions allows an attacker to access information which would otherwise be restricted, leading to Inf...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Jul 14, 2020 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 SAP NetWeaver AS JAVA (IIOP service) (SERVERCORE), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, and SAP NetWeaver AS JAVA (IIOP service) (CORE-TOOLS), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an at...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jul 14, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (BI Launchpad), version 4.2, does not sufficiently encode user-controlled inputs, resulting reflected in Cross-Site Scripting. |
1Sap 2Abap Platform Netweaver Application Server AbapJun 17, 2026 Jul 14, 2020 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 SAP NetWeaver (ABAP Server) and ABAP Platform, versions 731, 740, 750, allows an attacker with admin privileges to access certain files which should otherwise be restricted, leading to Information Disclosure. |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jul 14, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP Business Objects Business Intelligence Platform (BI Launchpad and CMC), versions 4.1, 4.2, allows to an attacker to embed malicious scripts in the application while uploading images, which gets executed when the vict...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jul 14, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (bipodata), version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. |
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag. |
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired. |