Sap
sap
1,589 CVEs • 430 products
Products (430)
Click to collapseToggle
Products (430)
Click to collapse
CVEs (1,589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure. |
SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed when opened, leading to CSV Command Injection. |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 Dec 11, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leading to Information Disclosure. |
1Sap 1Portfolio And Project Management Jun 17, 2026 Dec 11, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; unintentionally allows a user to discover accounting information of the Projects in Project dashboard...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before versions 4.1, 4.2 and 4.3, may lead to an authenticated user to send unintended request to the web...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Dec 11, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability. |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Nov 13, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can c...Show more |
SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation. |
Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization...Show more |
An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspec...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 13, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted. |
Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 13, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execu...Show more |
SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Nov 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this v...Show more |
SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service |
1Sap 3Dynamic Tier Sap IqSql AnywhereJun 17, 2026 Oct 8, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of...Show more |
Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure parameters’ default values to be part of the application logs leading to Information Disclosure. |
SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly when the default security provider is changed to BouncyCastle (BC), leading to Missing Authenticatio...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Oct 8, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not sufficiently encode user-controlled inputs and allows an attacker to store malicious scripts in the file...Show more |