Vulnerability index

Browse CVEs

1,134 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Focused Run MEDIUM 6.1
CVE-2022-24399

The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipar…

No fix yet
Fix from $1,600 2022-03-10
Business Objects Business Intelligence Platform MEDIUM 6.5
CVE-2022-24398

Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker to access informat…

No fix yet
Fix from $1,600 2022-03-10
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-24397

SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-…

Mitigation only
Fix from $1,600 2022-03-10
Netweaver Enterprise Portal MEDIUM 6.1
CVE-2022-24395

SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2022-03-10
Businessobjects Web Intelligence MEDIUM 5.4
CVE-2022-22546

Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Business Objects Web Intelligence…

Mitigation only
Fix from $1,600 2022-02-09
Content Server CRITICAL 10.0
CVE-2022-22536 KEVEPSS 98%

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulne…

Mitigation only
Fix from $2,300 2022-02-09
Netweaver Application Server Java CRITICAL 9.8
CVE-2022-22532

In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an u…

Mitigation only
Fix from $2,300 2022-02-09
Solution Manager CRITICAL 9.1
CVE-2022-22544

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents a…

Mitigation only
Fix from $2,300 2022-02-09
Adaptive Server Enterprise HIGH 7.8
CVE-2022-22528

SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, u…

Mitigation only
Fix from $1,950 2022-02-09
Netweaver Application Server Java HIGH 7.5
CVE-2022-22533

Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53…

Mitigation only
Fix from $1,950 2022-02-09
Netweaver Application Server Abap HIGH 7.5
CVE-2022-22540

SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, allows an attacker to execute cr…

Mitigation only
Fix from $1,950 2022-02-09
Netweaver Abap HIGH 7.5
CVE-2022-22543

SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87,…

Mitigation only
Fix from $1,950 2022-02-09
Erp Human Capital Management MEDIUM 6.5
CVE-2022-22535

SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees …

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22537

When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - versio…

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22538

When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - vers…

Mitigation only
Fix from $1,600 2022-02-09
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2022-22539

When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the…

Mitigation only
Fix from $1,600 2022-02-09
S\/4hana MEDIUM 6.5
CVE-2022-22542

S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Role, AND Enterprise Search for…

Mitigation only
Fix from $1,600 2022-02-09
Netweaver MEDIUM 6.1
CVE-2022-22534

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user …

Mitigation only
Fix from $1,600 2022-02-09
S\/4hana HIGH 8.1
CVE-2022-22530

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…

Mitigation only
Fix from $1,950 2022-01-14
S\/4hana HIGH 8.1
CVE-2022-22531

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files.…

Mitigation only
Fix from $1,950 2022-01-14
Enterprise Threat Detection MEDIUM 6.1
CVE-2022-22529

SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker p…

Mitigation only
Fix from $1,600 2022-01-14
Business One MEDIUM 5.5
CVE-2021-44234

SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expos…

Mitigation only
Fix from $1,600 2022-01-14
Commerce CRITICAL 9.8
CVE-2021-42064

If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce -…

Mitigation only
Fix from $2,300 2021-12-14
Abap Platform CRITICAL 9.8
CVE-2021-44231

Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control t…

Mitigation only
Fix from $2,300 2021-12-14
Access Control HIGH 8.8
CVE-2021-44233

SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which c…

Mitigation only
Fix from $1,950 2021-12-14
Saf T Framework HIGH 7.7
CVE-2021-44232

SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to ful…

Mitigation only
Fix from $1,950 2021-12-14
Netweaver Application Server Abap MEDIUM 6.7
CVE-2021-44235

Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow a…

Mitigation only
Fix from $1,600 2021-12-14
Knowledge Warehouse MEDIUM 6.1
CVE-2021-42063EPSS 22%

A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component with…

No fix yet
Fix from $1,600 2021-12-14
Businessobjects Business Intelligence Platform MEDIUM 5.4
CVE-2021-42061

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) - version 420, does not sufficiently encode user-controlled inputs, resulting i…

Mitigation only
Fix from $1,600 2021-12-14
Commerce HIGH 8.8
CVE-2021-40502

SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in es…

Mitigation only
Fix from $1,950 2021-11-10