Skip to main content

Vendor archive

sap CVEs

Beta · best-effort

1,580 CVEs tagged to vendor sap157 Critical, 458 High, 911 Medium, 54 Low, 0 Unrated.

CVE-2023-42476

Published Dec 12, 2023

SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the vict…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42480

Published Nov 14, 2023

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41366

Published Nov 14, 2023

Under certain condition SAP NetWeaver Application Server ABAP - versions KERNEL 722, KERNEL 7.53, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.91, KERNEL 7.92, KER…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-31403

Published Nov 14, 2023

SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and w…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-42477

Published Oct 10, 2023

SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confid…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-42475

Published Oct 10, 2023

The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentialit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42474

Published Oct 10, 2023

SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42473

Published Oct 10, 2023

S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges which has lo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41365

Published Oct 10, 2023

SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to info…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40310

Published Oct 10, 2023

SAP PowerDesigner Client - version 16.7, does not sufficiently validate BPMN2 XML document imported from an untrusted source. As a result, URLs of external entities in BPMN2 file,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40307

Published Sep 28, 2023

An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40625

Published Sep 12, 2023

S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an atta…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40624

Published Sep 12, 2023

SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an atta…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40623

Published Sep 12, 2023

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with opera…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40622

Published Sep 12, 2023

SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive informati…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-40621

Published Sep 12, 2023

SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed b…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40309

Published Sep 12, 2023

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2023-41369

Published Sep 12, 2023

The Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, 107, 108, allows an attacker to upload the XML file as an attachment. When click…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-41368

Published Sep 12, 2023

The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData cal…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-41367

Published Sep 12, 2023

Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40308

Published Sep 12, 2023

SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-37489

Published Sep 12, 2023

Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snipp…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 1,580 CVEsPage 8 of 64