Skip to main content

Vendor/product archive

sap / fiori_launchpad CVEs

Beta · best-effort

4 CVEs tagged to sap / fiori_launchpad0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-49584

Published Dec 12, 2023

SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, UI_700 200, SAP_BASIS 793, allows an attacker to use HTTP verb POST on read-…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26101

Published Mar 10, 2022

Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6283

Published Sep 9, 2020

SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parame…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6210

Published Mar 10, 2020

SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1