Skip to main content

Vendor/product archive

sap / business_planning_and_consolidation CVEs

Beta · best-effort

6 CVEs tagged to sap / business_planning_and_consolidation1 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-31407

Published May 9, 2023

SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After succe…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23851

Published Feb 14, 2023

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file forma…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0016

Published Jan 10, 2023

SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and co…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-41268

Published Dec 13, 2022

In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code r…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6368

Published Oct 15, 2020

SAP Business Planning and Consolidation, versions - 750, 751, 752, 753, 754, 755, 810, 100, 200, can be abused by an attacker, allowing them to modify displayed application conten…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16349

Published Aug 2, 2018

An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be reference…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1