Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35298

SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerab…

Mitigation only
Fix from $1,600 2022-09-13
Netweaver Application Server Abap MEDIUM 5.4
CVE-2022-35294

An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downl…

Mitigation only
Fix from $1,600 2022-09-13
Enable Now Manager CRITICAL 9.1
CVE-2022-35293

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, a…

Mitigation only
Fix from $2,300 2022-08-10
Businessobjects Business Intelligence HIGH 8.2
CVE-2022-32245

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive info…

Mitigation only
Fix from $1,950 2022-08-10
Successfactors Mobile HIGH 8.1
CVE-2022-35291

Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin …

Mitigation only
Fix from $1,950 2022-07-27
Businessobjects Business Intelligence Platform HIGH 8.8
CVE-2022-35228

SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This c…

Mitigation only
Fix from $1,950 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35225

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the net…

Mitigation only
Fix from $1,600 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35227

A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote att…

Mitigation only
Fix from $1,600 2022-07-12
Business One HIGH 8.8
CVE-2022-31593

SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by the application. An attacker co…

Mitigation only
Fix from $1,950 2022-07-12
Business One HIGH 7.5
CVE-2022-32249

Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access…

Mitigation only
Fix from $1,950 2022-07-12
Business One HIGH 7.5
CVE-2022-35168

Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the …

Mitigation only
Fix from $1,950 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-32247

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated …

Mitigation only
Fix from $1,600 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35170

SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the net…

Mitigation only
Fix from $1,600 2022-07-12
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-35172

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2022-07-12
Enterprise Portal MEDIUM 6.1
CVE-2022-35224

SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Si…

Mitigation only
Fix from $1,600 2022-07-12
Businessobjects Business Intelligence Platform MEDIUM 6.0
CVE-2022-35169

SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege to read and decrypt LCMBIAR …

Mitigation only
Fix from $1,600 2022-07-12
3d Visual Enterprise Viewer MEDIUM 5.5
CVE-2022-35171

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application cr…

Mitigation only
Fix from $1,600 2022-07-12
S\/4hana MEDIUM 5.4
CVE-2022-31597

Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does n…

Mitigation only
Fix from $1,600 2022-07-12
Business Objects Business Intelligence Platform MEDIUM 5.4
CVE-2022-31598

Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an a…

Mitigation only
Fix from $1,600 2022-07-12
S\/4hana MEDIUM 5.3
CVE-2022-32248

Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or…

Mitigation only
Fix from $1,600 2022-07-12
Businessobjects Bw Publisher Service HIGH 7.8
CVE-2022-31591

SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevate…

Mitigation only
Fix from $1,950 2022-07-12
Business One License Service Api HIGH 7.5
CVE-2022-28771

Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http re…

Mitigation only
Fix from $1,950 2022-07-12
Businessobjects Business Intelligence Platform MEDIUM 6.5
CVE-2022-29619

Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administrator to view, edit or modify …

Mitigation only
Fix from $1,600 2022-07-12
Adaptive Server Enterprise HIGH 8.8
CVE-2022-31595

SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of pri…

Mitigation only
Fix from $1,950 2022-06-14
Powerdesigner Proxy HIGH 7.8
CVE-2022-31590

SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root di…

Mitigation only
Fix from $1,950 2022-06-14
Adaptive Server Enterprise MEDIUM 6.7
CVE-2022-31594

A highly privileged user can exploit SUID-root program to escalate his privileges to root on a local Unix system.

No fix yet
Fix from $1,600 2022-06-14
Erp Financial Accounting MEDIUM 6.5
CVE-2022-31589

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than need…

Mitigation only
Fix from $1,600 2022-06-14
Netweaver Development Infrastructure MEDIUM 6.1
CVE-2022-29618

Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an …

Mitigation only
Fix from $1,600 2022-06-14
Host Agent MEDIUM 5.0
CVE-2022-29614

SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7…

No fix yet
Fix from $1,600 2022-06-14
Netweaver As Abap CRITICAL 9.8
CVE-2022-27668

Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProute…

No fix yet
Fix from $2,300 2022-06-14