Skip to main content

Vendor archive

sap CVEs

Beta · best-effort

1,580 CVEs tagged to vendor sap157 Critical, 458 High, 911 Medium, 54 Low, 0 Unrated.

CVE-2023-35873

Published Jul 11, 2023

The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user id…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35872

Published Jul 11, 2023

The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35871

Published Jul 11, 2023

The SAP Web Dispatcher - versions WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.85, WEBDISP 7.89, WEBDISP 7.91, WEBDISP 7.92, WEBDISP 7.93, KERNEL 7.53, KERNEL 7.54 KERNEL 7…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35870

Published Jul 11, 2023

When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33992

Published Jul 11, 2023

The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4C…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33990

Published Jul 11, 2023

SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and acc…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33989

Published Jul 11, 2023

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system fil…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33988

Published Jul 11, 2023

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Content-Security-Policy and X-XSS-Protection response header…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33987

Published Jul 11, 2023

An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDIS…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31405

Published Jul 11, 2023

SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in un…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33991

Published Jun 13, 2023

SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data f…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33986

Published Jun 13, 2023

SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabili…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33985

Published Jun 13, 2023

SAP NetWeaver Enterprise Portal - version 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerabili…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33984

Published Jun 13, 2023

SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32115

Published Jun 13, 2023

An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by t…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32114

Published Jun 13, 2023

SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2827

Published Jun 13, 2023

SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in t…

CVSS 7.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-32113

Published May 9, 2023

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32112

Published May 9, 2023

Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CO…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-32111

Published May 9, 2023

In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31407

Published May 9, 2023

SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After succe…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31406

Published May 9, 2023

Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted sit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31404

Published May 9, 2023

Under certain conditions, SAP BusinessObjects Business Intelligence Platform (Central Management Service) - versions 420, 430, allows an attacker to access information which would…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30744

Published May 9, 2023

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming an…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30743

Published May 9, 2023

Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows inje…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 226-250 of 1,580 CVEsPage 10 of 64