Skip to main content

Vendor archive

sap CVEs

Beta · best-effort

1,580 CVEs tagged to vendor sap157 Critical, 458 High, 911 Medium, 54 Low, 0 Unrated.

CVE-2023-40306

Published Sep 8, 2023

SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39440

Published Aug 8, 2023

In SAP BusinessObjects Business Intelligence - version 420, If a user logs in to a particular program, under certain specific conditions memory might not be cleared up properly,…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39437

Published Aug 8, 2023

SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-39436

Published Aug 8, 2023

SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover information relating to SRM within Vendor Master…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37491

Published Aug 8, 2023

The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRN…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37490

Published Aug 8, 2023

SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-37488

Published Aug 8, 2023

In SAP NetWeaver Process Integration - versions SAP_XIESR 7.50, SAP_XITOOL 7.50, SAP_XIAF 7.50, user-controlled inputs, if not sufficiently encoded, could result in Cross-Site Scr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37487

Published Aug 8, 2023

SAP Business One (Service Layer) - version 10.0, allows an authenticated attacker with deep knowledge perform certain operation to access unintended data over the network which co…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37486

Published Aug 8, 2023

Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be res…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37484

Published Aug 8, 2023

SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacke…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37483

Published Aug 8, 2023

SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36926

Published Aug 8, 2023

Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-36923

Published Aug 8, 2023

SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-33993

Published Aug 8, 2023

B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network to read or modify the SQL data…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36925

Published Jul 11, 2023

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an unauthenticated attacker to blindly execute HTTP requests. On successful exploitation, the attacker can cause a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36924

Published Jul 11, 2023

While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated att…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36922

Published Jul 11, 2023

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system comman…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36921

Published Jul 11, 2023

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned conte…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36919

Published Jul 11, 2023

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response header is not implemented, allowing…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36918

Published Jul 11, 2023

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36917

Published Jul 11, 2023

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old passw…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35874

Published Jul 11, 2023

SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KE…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 1,580 CVEsPage 9 of 64